Technical Information
- %WINDIR%\syswow64\calc.exe
- %APPDATA%\chromesvc.vbe
- %APPDATA%\microsoft\pagefile.inf
- %APPDATA%\microsoft\recycler\desktop.ini
- %APPDATA%\microsoft\recycler\null.vbe
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\startup\empty.lnk
- %APPDATA%\microsoft\pagefile.inf
- %APPDATA%\chromesvc.vbe
- 'cl###.dnss.zzux.com':443
- http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/CABD2A79A1076A31F21D253635CB039D4329A5E8.crt?6b##############
- 'cl###.dnss.zzux.com':443
- DNS ASK cl###.dnss.zzux.com
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\ChromeSvc.vbe"
- '%WINDIR%\syswow64\calc.exe'
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\ChromeSvc.vbe"' (with hidden window)
