Technical Information
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\Cvtres.exe'
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\Cvtres.exe
- %APPDATA%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\htKRzHJklNNL.lnk
- %APPDATA%\Roaming\hSILlzCwXBSr\8543.xml
- from %APPDATA%\Roaming\hSILlzCwXBSr\8543.xml to %APPDATA%\Roaming\hSILlzCwXBSr\hQ1Vb72t6bIX.exe
- DNS ASK dn#.##ftncsi.com
- DNS ASK q9###.no-ip.biz
- ClassName: 'Shell_TrayWnd' WindowName: ''