Technical Information
- '%TEMP%\INSTALL.EXE'
- '%TEMP%\nsy3.tmp\ns4.tmp' "CMD.EXE" /c %TEMP%\INSTALL.EXE"
- '%TEMP%\INSTALL.EXE' (downloaded from the Internet)
- '<SYSTEM32>\chcp.com' 1251
- '<SYSTEM32>\cmd.exe' /c 1.bat
- %TEMP%\nsy3.tmp\ns4.tmp
- %TEMP%\nsy3.tmp\System.dll
- <Current directory>\1.bat
- %TEMP%\nsy3.tmp\nsExec.dll
- %TEMP%\nsy2.tmp
- %TEMP%\nsy3.tmp\nsisdl.dll
- %TEMP%\INSTALL.CAB
- %TEMP%\nsy3.tmp\nsisdl.dll
- %TEMP%\nsy3.tmp\System.dll
- %TEMP%\nsy3.tmp\ns4.tmp
- %TEMP%\nsy3.tmp\nsExec.dll
- from %TEMP%\INSTALL.CAB to %TEMP%\INSTALL.EXE
- 'so####900098900.com':80
- so####900098900.com/files/install.cab
- DNS ASK so####900098900.com