Technical Information
- %WINDIR%\explorer.exe
- %TEMP%\2358.tmp
- %TEMP%\23c6.tmp
- %TEMP%\2406.tmp
- %TEMP%\26a5.tmp
- %TEMP%\29ae.tmp
- %TEMP%\29be.tmp
- %TEMP%\2a5b.tmp
- %TEMP%\2ac9.tmp
- %TEMP%\2af7.tmp
- %TEMP%\2b46.tmp
- %TEMP%\2358.tmp
- %TEMP%\23c6.tmp
- %TEMP%\2406.tmp
- %TEMP%\29ae.tmp
- %TEMP%\2a5b.tmp
- %TEMP%\2ac9.tmp
- %TEMP%\29be.tmp
- %TEMP%\2af7.tmp
- %TEMP%\2b46.tmp
- DNS ASK n7#####fhjwe90fujic.com
- DNS ASK m9######f0i4jfuienuif.com
- DNS ASK n3#######ejc90iejhnfiehc.com
- DNS ASK n3######ef8ehiwjfdichj.com
- DNS ASK n9######fj8eohicdnfuihe.com
- '%WINDIR%\syswow64\svchost.exe' netsvcs