Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'FastLinkAgent' = '%APPDATA%\FastLink\FastLinkAgent.exe'
- %TEMP%\nshc85e.tmp\killprocdll.dll
- %TEMP%\nshc85e.tmp\dllwaitforkillprogram.dll
- %APPDATA%\fastlink\fastlink.exe
- %APPDATA%\fastlink\fastlinkagent.exe
- %APPDATA%\fastlink\uninst.exe
- %TEMP%\nshc85e.tmp\selfdelete.dll
- C:\delus.bat
- %TEMP%\nshc85e.tmp\dllwaitforkillprogram.dll
- %TEMP%\nshc85e.tmp\killprocdll.dll
- %TEMP%\nshc85e.tmp\selfdelete.dll
- 're#.co.kr':80
- DNS ASK re#.co.kr
- '%APPDATA%\fastlink\fastlink.exe'
- '%WINDIR%\syswow64\cmd.exe' /c \DelUS.bat' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c \DelUS.bat