Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Yqjbm' = '%HOMEPATH%\mbjqY.url'
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bzjx5bke\navcancl[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\re1n75kr\errorpagetemplate[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0u8lpyu9\errorpagestrings[1]
- C:\users\public\libraries\temp
- %HOMEPATH%\links\yqjbmkop.exe
- %HOMEPATH%\links\yqjbm
- %HOMEPATH%\mbjqy.url
- C:\users\public\libraries\temp
- '1d#v.ws':443
- 'p8####.#b.files.1drv.com':443
- '79.##4.225.19':2556
- DNS ASK 1d#v.ws
- DNS ASK p8####.#b.files.1drv.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%ProgramFiles(x86)%\internet explorer\ieinstal.exe'