Technical Information
- %WINDIR%\Tasks\{791AC611-F2FD-40AE-9864-AB0C65F53148}.job
- '%TEMP%\<File name>.exe' /ver 1.1.5.26 e /fi {4328DE60-8A31-4FA1-88AB-F00C66E996BB}.txt
- '%TEMP%\nsv3.tmp\amisid.exe'
- '' (downloaded from the Internet)
- %TEMP%\taskSched.txt
- %TEMP%\<File name>.exe
- %TEMP%\nsq2.tmp
- %TEMP%\nsv3.tmp\NSIS_TaskScheduler.dll
- %TEMP%\nsv3.tmp\NSIS_AntiVmFraud.dll
- %TEMP%\nsv3.tmp\System.dll
- %TEMP%\nsv3.tmp\registry.dll
- %TEMP%\nsv3.tmp\nsisos.dll
- %TEMP%\nsv3.tmp\amisid.exe
- %WINDIR%\Tasks\{791AC611-F2FD-40AE-9864-AB0C65F53148}.job
- %TEMP%\nsv3.tmp\md5dll.dll
- %TEMP%\nsv3.tmp\inetc.dll
- 'www.eg###dx.tech':80
- http://www.eg###dx.tech/info.php?id######################################
- DNS ASK www.eg###dx.tech