Technical Information
- %ProgramFiles%\Microsoft SQL Server2\1.bat
- %ProgramFiles%\Microsoft SQL Server2\sany.exe
- %ProgramFiles%\Microsoft SQL Server2\lucifer616_4.exe
- %TEMP%\1.tmp\lucifer616.bat
- %ProgramFiles%\Microsoft SQL Server2\Coldedlucifer.exe
- %ProgramFiles%\Microsoft SQL Server2\Logger.exe
- %TEMP%\aut2.tmp
- %APPDATA%\Application.exe
- %TEMP%\aut3.tmp
- %APPDATA%\System.Data.SQLite.dll
- %TEMP%\dw.log
- %TEMP%\37204.dmp
- %TEMP%\aut2.tmp
- %TEMP%\aut3.tmp
- 'wp#d':80
- 'ip###ger.com':443
- http://11#.#11.111.1/wpad.dat via wp#d
- DNS ASK wp#d
- DNS ASK ip###ger.com
- ClassName: 'EDIT' WindowName: ''
- '%ProgramFiles%\Microsoft SQL Server2\sany.exe' -p123
- '%ProgramFiles%\Microsoft SQL Server2\lucifer616_4.exe'
- '%ProgramFiles%\Microsoft SQL Server2\Coldedlucifer.exe'
- '%APPDATA%\Application.exe'
- '%ProgramFiles%\Microsoft SQL Server2\Logger.exe'
- '<SYSTEM32>\cmd.exe' /c ""%ProgramFiles%\Microsoft SQL Server2\1.bat" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\lucifer616.bat" "
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1236