Technical Information
- '%WINDIR%\C8A63C84.exe'
- '%WINDIR%\E94676E9.exe'
- '<SYSTEM32>\cmd.exe' /c afc9fe2f418b00a0.bat
- '<SYSTEM32>\wscript.exe' "c:\D34FD3F5.vbs"
- '<SYSTEM32>\taskkill.exe' /f /im KSafeTray.exe
- %WINDIR%\C8A63C84.exe
- C:\D34FD3F5.vbs
- <Current directory>\jfumpbaxht
- <Current directory>\afc9fe2f418b00a0.bat
- %WINDIR%\BF.exe
- C:\1.INI
- %WINDIR%\E94676E9.exe
- %WINDIR%\BF.ini
- <SYSTEM32>\NOD32.ini
- %WINDIR%\BJ.exe
- <Current directory>\jfumpbaxht
- <Current directory>\1.INI
- from C:\1.INI to <Current directory>\1.INI
- '92####er.9966.org':521
- DNS ASK 92####er.9966.org
- ClassName: '(null)' WindowName: '??????????????'
- ClassName: '(null)' WindowName: '(null)'