Technical Information
- %WINDIR%\explorer.exe
- %WINDIR%\syswow64\autofmt.exe
- %WINDIR%\syswow64\autochk.exe
- %WINDIR%\syswow64\autoconv.exe
- http://www.de#####municacao.com/h3qo/?Ld############################################################################################
- DNS ASK su###yapasa.net
- DNS ASK sk####spirit.com
- DNS ASK de#####municacao.com
- '%WINDIR%\syswow64\ipconfig.exe'
- '%WINDIR%\syswow64\cmd.exe' del "<Full path to file>"