Technical Information
- %WINDIR%\Tasks\{21673DA3-35E9-4D5B-B7E3-9FD9F3C20522}.job
- %WINDIR%\Tasks\{D72E7867-BCC2-4ACB-81E5-2F1AF1EC5E2B}.job
- '%TEMP%\<File name>.exe' /ver 1.1.5.26 e /fi {F2A15937-C816-46E3-B4FD-6E5467602DA7}.txt
- '%TEMP%\nse3.tmp\amisid.exe'
- '' (downloaded from the Internet)
- %TEMP%\taskSched.txt
- <Current directory>\StubInstallerCleanUp.bat
- %TEMP%\nsz2.tmp
- %TEMP%\<File name>.exe
- %TEMP%\nse3.tmp\NSIS_TaskScheduler.dll
- %TEMP%\nse3.tmp\NSIS_AntiVmFraud.dll
- %TEMP%\nse3.tmp\System.dll
- %TEMP%\nse3.tmp\registry.dll
- %TEMP%\nse3.tmp\nsisos.dll
- %TEMP%\nse3.tmp\amisid.exe
- %WINDIR%\Tasks\{D72E7867-BCC2-4ACB-81E5-2F1AF1EC5E2B}.job
- %TEMP%\nse3.tmp\md5dll.dll
- %TEMP%\nse3.tmp\inetc.dll
- 'www.eg###dx.tech':80
- http://www.eg###dx.tech/info.php?id######################################
- DNS ASK www.eg###dx.tech