Technical Information
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'run' = 'c:\167515Tgpht167515\start.lnk'
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\start.lnk
- 'C:\167515Tgpht167515\csrss.exe' "c:\167515Tgpht167515\Hajf.dll",update
- '%TEMP%\IaJv.exe'
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 3
- '<SYSTEM32>\cmd.exe' /c 15626.bat
- <Current directory>\15626.bat
- C:\167515Tgpht167515\start.lnk
- C:\167515Tgpht167515\csrss.exe
- %TEMP%\IaJv.exe
- C:\167515Tgpht167515\Hajf.dll
- %TEMP%\IaJv.exe
- '<Private IP address>':8080
- 'aa.###aissmc.com':8023
- DNS ASK aa.###aissmc.com