Technical Information
- '%TEMP%\2.exe'
- '%TEMP%\is-43LBQ.tmp\1.tmp' /SL5="$300DE,3381035,54272,%TEMP%\1.exe"
- '%TEMP%\1.exe'
- '%TEMP%\2.exe' (downloaded from the Internet)
- %TEMP%\is-VEVAR.tmp\_isetup\_shfoldr.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\2[1].exe
- %TEMP%\2.exe
- %TEMP%\is-VEVAR.tmp\_isetup\_RegDLL.tmp
- %TEMP%\aut1.tmp
- %TEMP%\1.exe
- %TEMP%\is-43LBQ.tmp\1.tmp
- %TEMP%\aut1.tmp
- 'hi##0.com':80
- hi##0.com/2.exe
- DNS ASK hi##0.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'