Technical Information
- %HOMEPATH%\Start Menu\Programs\Startup\AdobeViewer.exe
- %APPDATA%\AdobeViewer.exe
- %APPDATA%\wayyouare.jpg
- 'ad#####ewer.no-ip.net':6969
- DNS ASK ad#####ewer.no-ip.net
- '%APPDATA%\AdobeViewer.exe'
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\shimgvw.dll,ImageView_Fullscreen %APPDATA%/wayyouare.jpg