Technical Information
- %TEMP%\stub.exe
- %TEMP%\stub.exe (downloaded from the Internet)
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '2500' = '00000003'
- %TEMP%\activation_key
- %TEMP%\nsd3.tmp\NSISdl.dll
- %TEMP%\stub.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\2774ppnojwkc[1].exe
- %TEMP%\nsd3.tmp\System.dll
- %TEMP%\nsw2.tmp
- <SYSTEM32>\{5135ae9d-df2a-786c-e0f4-c38b34eafda8}.dll-uninst.exe
- <SYSTEM32>\{5135ae9d-df2a-786c-e0f4-c38b34eafda8}.dll
- %TEMP%\nsd3.tmp\System.dll
- %TEMP%\nsd3.tmp\NSISdl.dll
- %TEMP%\activation_key
- 'av##v.com':80
- 'localhost':1039
- 'my####search.biz':80
- av##v.com/_jsuyxtsv/2774ppnojwkc.exe
- my####search.biz/nsi.php?af######################
- DNS ASK av##v.com
- DNS ASK my####search.biz