Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\<File name>.exe
- %APPDATA%\microsoft\windows\start menu\programs\startup\eezudu.exe
- <Drive name for removable media>:\eezudu.exe
- <Drive name for removable media>:\autorun.inf
- <Current directory>\rundli32.dll
- %ProgramFiles%\explorer.exe
- %ProgramFiles%\keygen.exe
- <SYSTEM32>\java\java.exe
- %TEMP%\user2.txt
- %APPDATA%\userlog.dat
- %TEMP%\user7
- %TEMP%\user8
- <Current directory>\rundli32.dll
- <Drive name for removable media>:\eezudu.exe
- <Drive name for removable media>:\autorun.inf
- <SYSTEM32>\java\java.exe
- %APPDATA%\userlog.dat
- %TEMP%\user2.txt
- %TEMP%\user8
- %TEMP%\user7
- %TEMP%\user8
- %TEMP%\user7
- DNS ASK ch####9.no-ip.biz
- '%ProgramFiles%\explorer.exe'
- '%ProgramFiles%\keygen.exe'
- '<SYSTEM32>\java\java.exe'
- '%ProgramFiles%\mozilla firefox\firefox.exe'