Technical Information
- System Restore (SR)
- %HOMEPATH%.SICOWIN\Application Data\Microsoft\Local\System.exe
- %TEMP%\Startup SImg.jpeg
- %HOMEPATH%.SICOWIN\Application Data\Microsoft\Local\System.exe
- %HOMEPATH%.SICOWIN\Application Data\Microsoft\Local\System.exe
- 'sm##.gmail.com':587
- DNS ASK sm##.gmail.com
- '<Private IP address>':1035