Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\bitef92.tmp
- '%HOMEPATH%\documents\jift.exe'
- %WINDIR%\syswow64\nslookup.exe
- C:\msdownld.tmp\as10c14e.tmp\new.exe
- %HOMEPATH%\documents\jift.exe
- %TEMP%\nsjcd84.tmp
- %TEMP%\isss.rtf
- %TEMP%\ult_icp.png
- %TEMP%\aaa.dll
- %TEMP%\nszcecd.tmp\system.dll
- %PROGRAMDATA%\zkgzol.png
- %APPDATA%\data\logs.dat
- %APPDATA%\microsoft\windows\start menu\programs\startup\bitef92.tmp
- C:\msdownld.tmp\as10c14e.tmp\new.exe
- http://20#.#85.126.240/new.exe
- DNS ASK xy###5.spdns.de
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- '%HOMEPATH%\documents\jift.exe' ' (with hidden window)
- '%WINDIR%\syswow64\nslookup.exe'