Technical Information
- '' (downloaded from the Internet)
- %TEMP%\syswnt.exe
- %TEMP%\_uninsep.bat
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\apss32[1].dll0
- %TEMP%\mmmm.exe
- <Full path to file>
- %TEMP%\syswnt.exe
- 'ne##ee.com':80
- http://ne##ee.com/CloneFile/apss32.dll0
- DNS ASK ne##ee.com
- '%TEMP%\syswnt.exe'
- '%TEMP%\mmmm.exe'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\_uninsep.bat" "