Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '1du9we8r394r34ra' = '%APPDATA%\<File name>.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Audio HD Driver' = '%TEMP%\AutoStart.exe'
- hidden files
- %APPDATA%\<File name>.exe
- %APPDATA%\explorer.exe
- %TEMP%\autostart.exe
- %APPDATA%\<File name>.exe
- %TEMP%\autostart.exe
- http://www.se##aos.net/
- http://www.ha###siz.net/Webpanel/connect.php
- DNS ASK ha###siz.net
- DNS ASK se##aos.net
- '%APPDATA%\explorer.exe'