Technical Information
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\WinRAR.exe
- '%TEMP%\is-B92JP.tmp\11.13-јтЅа°ж.tmp' /SL5="$40036,7270015,56835,%WINDIR%\temp\11.13-јтЅа°ж.exe"
- '%WINDIR%\Temp\111.EXE'
- '%WINDIR%\Temp\11.13-јтЅа°ж.exe'
- '%WINDIR%\Temp\9999922.exe'
- %TEMP%\is-B92JP.tmp\11.13-јтЅа°ж.tmp
- %TEMP%\is-PP7VI.tmp\_isetup\_shfoldr.dll
- %WINDIR%\Temp\9999922.exe
- %WINDIR%\Temp\11.13-јтЅа°ж.exe
- %WINDIR%\Temp\111.EXE
- '<Private IP address>':2014
- '12#.#14.52.222':2015
- '12#.#0.132.173':2014
- ClassName: '' WindowName: '456УОП·ЦРРД'
- ClassName: '' WindowName: '456????????'
- ClassName: 'Shell_TrayWnd' WindowName: ''