Technical Information
- '<LS_APPDATA>\{LGBP0AVA-9QVS-2QZF-OFX1-7TQ5DA1LSHKS}\j0ftjmea3gbn.exe'
- '<LS_APPDATA>\{LGBP0AVA-9QVS-2QZF-OFX1-7TQ5DA1LSHKS}\02h9fozhd.exe'
- '<LS_APPDATA>\{LGBP0AVA-9QVS-2QZF-OFX1-7TQ5DA1LSHKS}\j0ftjmea3gbn.exe' (downloaded from the Internet)
- '<LS_APPDATA>\{LGBP0AVA-9QVS-2QZF-OFX1-7TQ5DA1LSHKS}\02h9fozhd.exe' (downloaded from the Internet)
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- <LS_APPDATA>\{LGBP0AVA-9QVS-2QZF-OFX1-7TQ5DA1LSHKS}\j0ftjmea3gbn.exe
- <LS_APPDATA>\{LGBP0AVA-9QVS-2QZF-OFX1-7TQ5DA1LSHKS}\02h9fozhd.exe
- <SYSTEM32>\PerfStringBackup.TMP
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- '17#.#1.151.173':80
- 17#.#1.151.173/administrator/opclients.bmp
- 17#.#1.151.173/administrator/caplis.bmp
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'TMyDwnSmigoFrm' WindowName: ''