Technical Information
- %HOMEPATH%\Start Menu\Programs\Startup\AppLocale.lnk
- '%TEMP%\is-R7PD8.tmp\HF pAppLoc1.1.2.tmp' /SL5="$20102,1195423,119296,%TEMP%\HF pAppLoc1.1.2.exe"
- '%TEMP%\HF pAppLoc1.1.2.exe'
- '%ALLUSERSPROFILE%\Application Data\AppLocale\AppLocale.exe'
- <SYSTEM32>\wbem\wmiprvse.exe
- C:\7d79ea35ac76c79f5363cb1dc5afa5213e0e8b6c
- %TEMP%\HF pAppLoc1.1.2.exe
- %HOMEPATH%\My Documents\lvpuinpj.ijc
- C:\7d79ea35ac76c79f5363cb1dc5afa5213e0e8b6c
- from %HOMEPATH%\My Documents\lvpuinpj.ijc to %ALLUSERSPROFILE%\Application Data\AppLocale\AppLocale.exe
- 'ts.#hiro.pw':1902
- DNS ASK ts.#hiro.pw
- ClassName: 'Shell_TrayWnd' WindowName: ''