Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\WinHelp32] 'Start' = '00000002'
- '%PROGRAM_FILES%\Internet Explorer\WinHelp32.exe'
- '%TEMP%\RarSFX0\122333.exe'
- '%TEMP%\RarSFX0\UHARC.EXE' e thing.uha
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- %TEMP%\RarSFX0\122333.exe
- %PROGRAM_FILES%\Internet Explorer\WinHelp32.exe
- %TEMP%\RarSFX0\thing.uha
- %TEMP%\RarSFX0\UHARC.EXE
- %PROGRAM_FILES%\Internet Explorer\WinHelp32.exe
- %TEMP%\RarSFX0\UHARC.EXE
- %TEMP%\RarSFX0\thing.uha
- %TEMP%\RarSFX0\122333.exe
- 'sh###ye.00o.pw':8086
- DNS ASK sh###ye.00o.pw
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''