Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'frm_Navnefringernes' = 'wscript "%HOMEPATH%\frm_Turnkeys\frm_STAVREDE.vbs"'
- %WINDIR%\win.ini
- '' (downloaded from the Internet)
- '%TEMP%\ypgyzska.exe'
- frm_stavrede.exe
- <LS_APPDATA>\microsoft\windows\<INETFILES>\content.ie5\caasbycl\chiefo[1].exe
- %TEMP%\ypgyzska.exe
- %HOMEPATH%\frm_turnkeys\frm_stavrede.exe
- %HOMEPATH%\frm_turnkeys\frm_stavrede.vbs
- %APPDATA%\remcos\logs.dat
- 'pe####a.hopto.org':4344
- http://pe#####.warzonedns.com:8080/bin/chiefo.exe
- DNS ASK pe#####.warzonedns.com
- DNS ASK pe####a.hopto.org
- '%HOMEPATH%\frm_turnkeys\frm_stavrede.exe'
- '%ProgramFiles%\microsoft office\office14\excel.exe' -Embedding