Technical Information
- %APPDATA%\yujeu.exe
- %TEMP%\czxlbvhtmwf
- %APPDATA%\yujeu.exe
- http://pi#####orld.free-h.fr/?ac#####################################################
- DNS ASK au######on.whatismyip.com
- DNS ASK pi#####orld.free-h.fr
- '%APPDATA%\yujeu.exe' <Full path to file>
- '%APPDATA%\yujeu.exe' <Full path to file>' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\dw20.exe' -x -s 912