Technical Information
- %TEMP%\e_80003\krnln.fnr
- %TEMP%\e_80003\dp1.fne
- %TEMP%\e_80003\com.run
- %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012020021420200215\index.dat
- http://ad.##inawg.net/pop.htm
- http://ad.##inawg.net/
- http://ad.##inawg.net/favicon.ico
- DNS ASK ad.##inawg.net
- DNS ASK hm.##idu.com
- DNS ASK 69##88.com
- DNS ASK go#####agmanager.com
- DNS ASK go#####analytics.com
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\FirewallControlPanel.dll,ShowNotificationDialog /configure /ETOnly 0 /OnProfiles 6 /OtherAllowed 0 /OtherBlocked 0 /OtherEdgeAllowed 0 /NewBlocked 2 "<Full path to file>"
- '%WINDIR%\syswow64\explorer.exe' http://ad.##inawg.net/pop.htm