Technical Information
- %HOMEPATH%\Start Menu\Programs\Startup\xssGnDe.com.url
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\svchost.exe
- %APPDATA%\folder\file.exe
- %TEMP%\aut1.tmp
- %HOMEPATH%\Local Settings\TempbIRJF.Qz
- %APPDATA%\folder\file.exe
- %HOMEPATH%\Local Settings\TempbIRJF.Qz
- %TEMP%\aut1.tmp
- '<SYSTEM32>\svchost.exe'