Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Local Security Authortity Process' = '%APPDATA%\Microsoft\lsass.exe'
- %APPDATA%\Microsoft\lsass.exe
- %APPDATA%\7za.exe x "%APPDATA%\Microsoft\a1.7z" -aoa -o"%APPDATA%\Microsoft" -psmells
- %APPDATA%\Microsoft\n
- %TEMP%\nsl3.tmp\ExecDos.dll
- %APPDATA%\Microsoft\lsass.exe
- %TEMP%\nsk2.tmp
- %APPDATA%\7za.exe
- %APPDATA%\Microsoft\a1.7z
- %TEMP%\nsl3.tmp\ExecDos.dll
- 'me####tarsoft.net':80
- me####tarsoft.net/maxxx/submit.php?mo##########################################################################################################
- me####tarsoft.net/maxxx/submit.php
- me####tarsoft.net/maxxx/submit.php?mo######################
- DNS ASK me####tarsoft.net