Technical Information
- %WINDIR%\SysWOW64\msvcr71.dll with %WINDIR%\syswow64\~glh0001.tmp
- %TEMP%\glbe5a.tmp
- %TEMP%\glcfd1.tmp
- %TEMP%\glkff1.tmp
- %TEMP%\glm13e9.tmp
- %TEMP%\glw19c6.tmp
- %TEMP%\glg1fb4.tmp
- %TEMP%\~glh0000.tmp
- %WINDIR%\syswow64\~glh0001.tmp
- %TEMP%\glw19c6.tmp
- %WINDIR%\syswow64\msvcr71.dll
- from %TEMP%\~glh0000.tmp to %TEMP%\glf2090.tmp
- DNS ASK ac###tica.com
- DNS ASK ac#####ca1.cachefly.net
- '%TEMP%\glbe5a.tmp' 6144 <Full path to file>