Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'winhlp32' = '%WINDIR%\MeCagoentuCompu\curriculum.exe'
- file extensions
- '<SYSTEM32>\cscript.exe' %WINDIR%\MeCagoentuCompu\open-music.vbs
- '<SYSTEM32>\cscript.exe' %WINDIR%\install.vbs
- %WINDIR%\MeCagoentuCompu\crnjeufu.html
- %WINDIR%\MeCagoentuCompu\open-music.vbs
- %WINDIR%\MeCagoentuCompu\songs.txt
- %WINDIR%\MeCagoentuCompu\logMaster.txt
- %WINDIR%\install.vbs
- %WINDIR%\MeCagoentuCompu\curriculum.exe
- %WINDIR%\factura.exe
- 'sm##.gmail.com':587
- DNS ASK sm##.gmail.com
- ClassName: 'Shell_TrayWnd' WindowName: ''