Technical Information
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'zxzz' = '%APPDATA%\zxzx.exe'
- %APPDATA%\zxzzzz.txt
- %APPDATA%\zxzx.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0_32\usagelogs\<File name>.exe.log
- %APPDATA%\1.txt
- 'sites.google.com':443
- 'sites.google.com':443
- DNS ASK sites.google.com
- '%APPDATA%\zxzx.exe'