Technical Information
- <SYSTEM32>\dsound.dll with <SYSTEM32>\dsound.dll.mod
- <SYSTEM32>\mshtml.dll with <SYSTEM32>\mshtml.dll.mod
- %WINDIR%\pyBVWWu.exe
- <SYSTEM32>\cmd.exe /c """%TEMP%\delself.bat"" "
- <SYSTEM32>\iFwoX.cUW
- %TEMP%\iFwoX.cUW
- %TEMP%\ComB.tmp
- %TEMP%\delself.bat
- <SYSTEM32>\dsound.dll.mod
- <SYSTEM32>\mshtml.dll.mod
- %TEMP%\Зї»Ї.exe
- %TEMP%\$filenumber.txt
- %TEMP%\$filenumbere.txt
- %WINDIR%\pyBVWWu.exe
- %TEMP%\ComA.tmp
- %TEMP%\DNFёЁЦъОДјю.exe
- %TEMP%\DNFёЁЦъОДјю.exe
- %TEMP%\$filenumber.txt
- %TEMP%\$filenumbere.txt
- from <SYSTEM32>\dsound.dll to <SYSTEM32>\dsound.dllOheCj
- from <SYSTEM32>\mshtml.dll to <SYSTEM32>\mshtml.dllRqBhD
- ClassName: '' WindowName: '12345'
- ClassName: 'TWINCONTROL' WindowName: '????????????'
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '54321' WindowName: '12345'