Technical Information
- %TEMP%\caycodx.hflynpenyeoh
- %TEMP%\jfcwsobwi.txt
- http://ad#.#ensa.at/api1/b3OCse6e8A6AhEjNfpPfc/uoTTDG2pFD3hMP9p/zx4ocP_2FE2iHZ3/94e0qWFjYrhKcQCVj_/2BbF76QQM/Dmc1iq2m9APDHKyQqaf0/0yPi2XWz_2FGKQoKFFy/bZ_2F_2FcOyqjs_2BrkdZL/WyyJcYB3nFAkg/cvooX3...
- DNS ASK ad#.#ensa.at
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '<SYSTEM32>\regsvr32.exe' -s %TEMP%\\jFcWSOBWi.txt