Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '<File name>.exe' = '%APPDATA%\eampEZbk\uoSiBVoi\4.17.45.9155\<File name>.exe'
- %WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe
- %TEMP%\keymaker.exe
- %APPDATA%\eampezbk\uosibvoi\4.17.45.9155\<File name>.exe
- %APPDATA%\eampezbk\uosibvoi\4.17.45.9155\<File name>.exe
- '255.255.255.255':1605
- DNS ASK bo####23.no-ip.org
- ClassName: '' WindowName: '[ A G A i N ]'
- '%TEMP%\keymaker.exe'
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe'