Technical Information
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'DH7XN6X0GXL' = '%ProgramFiles(x86)%\Mj4-tcda8\rlhdutzx.exe'
- %WINDIR%\explorer.exe
- iexplore.exe process, wininet.dll module
- firefox.exe process, nss3.dll module
- %WINDIR%\syswow64\autofmt.exe
- %HOMEPATH%\desktop\000814251_video_01.avi
- %TEMP%\mj4-tcda8\rlhdutzx.exe
- %ProgramFiles(x86)%\mj4-tcda8\rlhdutzx.exe
- %APPDATA%\6qm6naqe\6qmlogri.ini
- http://www.fa#####flaremusic.com/f90/?ch################################################################################################
- DNS ASK fa#####flaremusic.com
- '%ProgramFiles(x86)%\mj4-tcda8\rlhdutzx.exe'
- '%WINDIR%\syswow64\systray.exe'
- '%WINDIR%\syswow64\cmd.exe' del "<Full path to file>"
- '%ProgramFiles(x86)%\mozilla firefox\firefox.exe'