Technical Information
- <SYSTEM32>\<Virus name>ex.exe
- <SYSTEM32>\<Virus name>.exe
- <SYSTEM32>\cmd.exe /c .\DelMe.bat
- <SYSTEM32>\<Virus name>ex.exe
- <SYSTEM32>\<Virus name>.exe
- <Current directory>\DelMe.bat
- 'xs##g.com':32502
- 'xt##h.com':32502
- 'localhost':1036
- 'an.###hsg8090.com':222
- DNS ASK xt##h.com
- DNS ASK xs##g.com
- DNS ASK an.###hsg8090.com