Technical Information
- '%TEMP%\ireset-1.2_tmp.exe'
- '%TEMP%\ireset-1.2.exe'
- '%TEMP%\ireset-1.2_tmp.exe' (downloaded from the Internet)
- %TEMP%\ireset-1.2_tmp.exe
- %TEMP%\ireset-1.2.exe
- %TEMP%\nsm2.tmp\NSISdl.dll
- %TEMP%\nsm2.tmp\NSISdl.dll
- '4k###sions.biz':80
- 4k###sions.biz/gsver/gsver.php?sf#######################
- DNS ASK 4k###sions.biz
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'