Technical Information
- '%TEMP%\uninst.exe'
- '%TEMP%\~nsu.tmp\Au_.exe' _?=%TEMP%\
- '%TEMP%\8482.exe'
- '%TEMP%\8482.exe' (downloaded from the Internet)
- %TEMP%\uninst.exe
- %TEMP%\temp.ini
- %TEMP%\nst3.tmp\System.dll
- %TEMP%\nsv7.tmp
- %TEMP%\~nsu.tmp\Au_.exe
- %TEMP%\nsw5.tmp
- %TEMP%\8482.exe
- %TEMP%\nst3.tmp\InetLoad.dll
- %TEMP%\nst3.tmp\nsRandom.dll
- %TEMP%\nse2.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\down[1].php
- %APPDATA%\Microsoft\Media Player\MediaPlayer.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\down[1].php
- %TEMP%\uninst.exe
- %TEMP%\temp.ini
- %TEMP%\nst3.tmp\System.dll
- %TEMP%\nst3.tmp\InetLoad.dll
- %TEMP%\nst3.tmp\nsRandom.dll
- 's2##.#esthh.info':80
- s2##.#esthh.info/down.php?i=####
- DNS ASK s2##.#esthh.info
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'