Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\hjdytuap.exe
- '' (downloaded from the Internet)
- '%APPDATA%\vbc.exe'
- %WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe
- %APPDATA%\vbc.exe
- %APPDATA%\36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee\run.dat
- 'co######balupdate.myftp.biz':83
- '18#.#44.30.251':83
- http://co######balupdate.myftp.biz/nass.exe
- DNS ASK co######balupdate.myftp.biz
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe'