Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '98212527' = '%ALLUSERSPROFILE%\Application Data\98212527\98212527.exe'
- '%ALLUSERSPROFILE%\Application Data\98212527\98212527.exe' Data\98212527\98212527.exe /inst
- '<SYSTEM32>\cmd.exe' /c ""%ALLUSERSPROFILE%\Application Data\98212527\98212527.bat" "
- %ALLUSERSPROFILE%\Application Data\98212527\98212527.bat
- %ALLUSERSPROFILE%\Application Data\98212527\98212527.exe
- '89.##8.174.95':80
- 89.##8.174.95/in.php?af#########################################
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'