Technical Information
- [<HKCU>\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN] 'Adobe Reader Speed Launch' = '%TEMP%\Reader_sl.exe'
- %TEMP%\reader_sl.exe
- <Full path to file>
- %TEMP%\reader_sl.exe
- DNS ASK gl###lowa.com
- '%TEMP%\reader_sl.exe'
- '%WINDIR%\syswow64\cmd.exe' /c del <Full path to file> /a > nul' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c del <Full path to file> /a > nul