Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\ee858e.lnk
- %TEMP%\e_n4\krnln.fnr
- %TEMP%\e_n4\dp1.fne
- %WINDIR%\syswow64\8cdd49\dp1.fne
- %WINDIR%\syswow64\8cdd49\krnln.fnr
- %WINDIR%\syswow64\8cdd49\w804eb9.exe
- %WINDIR%\syswow64\8cdd49\eapi.fne
- %WINDIR%\syswow64\8cdd49\htmlview.fne
- %WINDIR%\syswow64\8cdd49\internet.fne
- %WINDIR%\syswow64\8cdd49\w804eb9.txt
- '%WINDIR%\syswow64\8cdd49\w804eb9.exe'
- '%WINDIR%\syswow64\explorer.exe' <Current directory>\