Technical Information
- %TEMP%\rbgua.eqhocnyc
- %TEMP%\ylhj.txt
- http://ad#.#ensa.at/api1/yTfAv_2FBVDn_2/FJ_2FLiO_2F59lrbCcxC0/6Rk8_2FxJUdDWj7e/kcgyHLM7pgGgvH9/SWq68YRre60KJ1o0wq/trYKxhp8o/Q4beviAuNHS790EpSxhq/gsqvyu62NnNSsekA64B/OC807QrRNmdBiM5ZPNbWCt/rxW62...
- DNS ASK ad#.#ensa.at
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '<SYSTEM32>\regsvr32.exe' -s %TEMP%\\YLHJ.txt