Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'updater' = '%WINDIR%\Driver Cache\i386\Temp\wfdmgr.exe'
- '%WINDIR%\Driver Cache\i386\Temp\wfdmgr.exe'
- '%WINDIR%\Driver Cache\i386\Temp\program.exe'
- '<SYSTEM32>\attrib.exe' +s +h Temp
- '<SYSTEM32>\cmd.exe' /c attrib +s +h Temp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\ip[1]
- %TEMP%\~ip.tmp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\U98D4X8H\whatsmyip[1]
- %WINDIR%\Driver Cache\i386\Temp\program.exe
- %TEMP%\aut1.tmp
- %WINDIR%\Driver Cache\i386\Temp\wfdmgr.exe
- %TEMP%\aut2.tmp
- %TEMP%\~ip.tmp
- %TEMP%\aut2.tmp
- %TEMP%\aut1.tmp
- %TEMP%\~ip.tmp
- 'www.wh###myip.us':80
- 'ip.nu':80
- http://www.wh###myip.us/
- http://ip.nu/
- DNS ASK www.wh###myip.us
- DNS ASK ip.nu