Technical Information
- %WINDIR%\de5148ff.reg
- %ProgramFiles%\internet explorer\acpi.vxd
- %ProgramFiles%\internet explorer\_file0000.tmp
- %WINDIR%\system\<File name>.exe
- %WINDIR%\de5148ff.reg
- %ProgramFiles%\internet explorer\acpi.vxd
- %WINDIR%\de5148ff.reg
- %ProgramFiles%\internet explorer\acpi.vxd
- DNS ASK rc###rtinez.com
- DNS ASK cl######ebenelli.globat.com
- ClassName: '145432A' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- '%WINDIR%\syswow64\regedit.exe' /s %WINDIR%\DE5148FFReg' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' /s %WINDIR%\DE5148FFReg