Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\winnetsvc_ji3i68g3g.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0_32\usagelogs\<File name>.exe.log
- %TEMP%\fss4gnl4.ord
- %TEMP%\fss4gnl4.ord
- 'al#####pdate.pages.dev':443
- DNS ASK al#####pdate.pages.dev
- '%APPDATA%\microsoft\windows\start menu\programs\startup\winnetsvc_ji3i68g3g.exe'
- '%APPDATA%\microsoft\windows\start menu\programs\startup\winnetsvc_ji3i68g3g.exe' ' (with hidden window)