Technical Information
- <SYSTEM32>\cmd.exe /c .\ranuloup_1s.bat
- <SYSTEM32>\rundll32.exe "%TEMP%\efs1.tmp",MainDo <Full path to virus>
- <SYSTEM32>\regsvr32.exe -s "%WINDIR%\fs32.dll"
- <Current directory>\ranuloup_1s.bat
- %TEMP%\efs1.tmp
- %WINDIR%\fs32.dll
- %TEMP%\efs1.tmp
- 'cn#.#zads.cn':802
- DNS ASK cn#.#zads.cn
- ClassName: 'MS_WINHELP' WindowName: ''