Technical Information
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'abanet' = '%APPDATA%\Microsoft\Windows\Templates\fireboard.exe'
- %WINDIR%\syswow64\svchost.exe
- [HKCU\Software\FTPWare\COREFTP\Sites\]
- [HKCU\Software\Martin Prikryl\WinSCP 2\Sessions\]
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %APPDATA%\opera software\opera stable\login data
- %LOCALAPPDATA%\microsoft\edge\user data\default\login data
- %LOCALAPPDATA%\microsoft\edge\user data\default\web data
- %TEMP%\autd364.tmp
- %TEMP%\retrofits
- %TEMP%\autd5f5.tmp
- %TEMP%\jinrikisha
- %APPDATA%\microsoft\windows\templates\dgtsubyyfl-user\logindata
- %APPDATA%\microsoft\windows\templates\dgtsubyyfl-user\webdata
- %APPDATA%\microsoft\windows\templates\dgtsubyyfl-user\global-messages
- %APPDATA%\microsoft\windows\templates\fireboard.exe
- %TEMP%\autd364.tmp
- %TEMP%\autd5f5.tmp
- %APPDATA%\microsoft\windows\templates\dgtsubyyfl-user\global-messages
- 'sh##ip.net':80
- http://sh##ip.net/
- DNS ASK sh##ip.net
- '%WINDIR%\syswow64\svchost.exe'