Technical Information
- '<SYSTEM32>\cmd.exe' /c rundll32 %HOMEPATH%\zx.tmp Mickey TZHyZ16ZwZZGZlUZthHpZb2ZrhHmZ16ZWhHiZ1VZtSHNZb2Z4ZHDZbjZWSH3Z1wZwhHxZbsZWZHDZbsZ46ZpZb7ZWhHNZZ!!
- %HOMEPATH%\zx.tmp
- http://ne######.medianewsonline.com/KB2534111.dat
- DNS ASK ne######.medianewsonline.com
- '<SYSTEM32>\cmd.exe' /c rundll32 %HOMEPATH%\zx.tmp Mickey TZHyZ16ZwZZGZlUZthHpZb2ZrhHmZ16ZWhHiZ1VZtSHNZb2Z4ZHDZbjZWSH3Z1wZwhHxZbsZWZHDZbsZ46ZpZb7ZWhHNZZ!!' (with hidden window)
- '<SYSTEM32>\rundll32.exe' %HOMEPATH%\zx.tmp Mickey TZHyZ16ZwZZGZlUZthHpZb2ZrhHmZ16ZWhHiZ1VZtSHNZb2Z4ZHDZbjZWSH3Z1wZwhHxZbsZWZHDZbsZ46ZpZb7ZWhHNZZ!!