Technical Information
- '%ProgramFiles%\Windows NT\dialer.exe'
- aion.exe
- ash.exe
- ageofconan.exe
- dialer.exe
- 360tray.exe
- %TEMP%\gfa.beb
- %ALLUSERSPROFILE%\xis\ogrbab.cwx
- from <Full path to file> to %TEMP%\1.tmp
- 'ef###nsrey.com':80
- http://ze##er.com/y2thcs3aum/index.php via ef###nsrey.com
- http://ca##ax.com/y2thcs3aum/index.php via ef###nsrey.com
- DNS ASK ef###nsrey.com
- DNS ASK microsoft.com
- DNS ASK google.com
- DNS ASK sw###yurof.com