Technical Information
- [<HKLM>\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN] 'Microsoft В© Cooperation 2007' = '%APPDATA%\Microsoft\Windows\Templates\explorer.exe'
- [<HKCU>\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN] 'Microsoft В© Cooperation 2007' = '%APPDATA%\Microsoft\Windows\Templates\explorer.exe'
- %ALLUSERSPROFILE%\start menu\programs\startup\explorer.exe
- hidden files
- %APPDATA%\microsoft\windows\templates\explorer.exe
- %APPDATA%\microsoft\windows\templates\explorer.exe
- DNS ASK re####ok.redio.de
- '%APPDATA%\microsoft\windows\templates\explorer.exe'
- '%APPDATA%\microsoft\windows\templates\explorer.exe' ' (with hidden window)