Technical Information
- <SYSTEM32>\msvcr100.dll
- '<SYSTEM32>\cmd.exe' /c icacls <SYSTEM32>\ncrypt.dll /reset
- '<SYSTEM32>\cacls.exe' <SYSTEM32>\ncrypt.dll /G yedogawa:F
- '<SYSTEM32>\cmd.exe' /c takeown /f <SYSTEM32>\ncrypt.dll
- '<SYSTEM32>\cmd.exe' /c cacls <SYSTEM32>\ncrypt.dll /G yedogawa:F
- <SYSTEM32>\COMDLG32.OCX
- %TEMP%\~DF2AFB.tmp
- <SYSTEM32>\MSINET.OCX
- <SYSTEM32>\MSCOMCTL.OCX
- <DRIVERS>\etc\hosts
- 'pe####nganindo.com':80
- 'localhost':1036
- http://pe####nganindo.com/fileindo2/dummer26.txt
- DNS ASK pe####nganindo.com