Technical Information
- %WINDIR%\microsoft.net\framework\v4.0.30319\aspnet_compiler.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\addinprocess.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\addinprocess32.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\addinutil.exe
- %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012020042820200429\index.dat
- http://ch#####.amazonaws.com/
- http://www.ge###ugin.net/json.gp?ip###############
- http://17#.##7.91.34:6677/IRemotePanel via 17#.#57.91.34
- DNS ASK kx.#####disperfectshild.ru
- DNS ASK ch#####.amazonaws.com
- DNS ASK ge###ugin.net
- ClassName: 'DDEMLMom' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- ClassName: 'Static' WindowName: ''
- '%WINDIR%\microsoft.net\framework\v4.0.30319\aspnet_compiler.exe'