Technical Information
- %HOMEPATH%\Start Menu\Programs\Startup\IBbAZGGaKSCC.lnk
- '%WINDIR%\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe'
- '%APPDATA%\bdWB.exe' "%APPDATA%\PFPWZ.au3"
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe
- %APPDATA%\PFPWZ.au3
- %APPDATA%\bdWB.exe
- %HOMEPATH%\rmsRueKNRXFWZCo9\PFPWZ.au3
- %HOMEPATH%\rmsRueKNRXFWZCo9\bdWB.exe
- from %APPDATA%\bdWB.exe to %HOMEPATH%\rmsRueKNRXFWZCo9\bdWB.exe
- from %APPDATA%\PFPWZ.au3 to %HOMEPATH%\rmsRueKNRXFWZCo9\PFPWZ.au3
- 'su#####win.dyndns.pro':10302
- 'mi######t01.system-ns.net':10302
- DNS ASK Su#####Win.dyndns.pro
- DNS ASK Mi######t01.System-NS.net
- ClassName: 'Shell_TrayWnd' WindowName: ''