Technical Information
- [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] '42y04b91Scx' = '%APPDATA%\agegsgsbg\D6KrLe_y28o3X9\42y04b91Scx.exe'
- %APPDATA%\agegsgsbg\d6krle_y28o3x9\42y04b91scx.txt
- %APPDATA%\agegsgsbg\d6krle_y28o3x9\42y04b91scx.exe
- %APPDATA%\agegsgsbg\d6krle_y28o3x9\nvsmartmax.dll
- %LOCALAPPDATA%\1fcbfbff000606a6
- %APPDATA%\agegsgsbg\d6krle_y28o3x9\.lnk
- %APPDATA%\agegsgsbg\d6krle_y28o3x9\.lnk
- '99##.#201314999.com':8080
- '99##.#201314999.com':12345
- http://99##.###1314999.com:8080/10x.dll via 99##.#201314999.com
- '99##.#201314999.com':12345
- DNS ASK 99##.#201314999.com
- ClassName: '' WindowName: ''
- '%APPDATA%\agegsgsbg\d6krle_y28o3x9\42y04b91scx.exe'
- '<Full path to file>' 45063C065A06530675066306740675065A0673067506630674065A0647067606760642066706720667065A065406690667066B066F06680661065A066706610663066106750661067506640661065A06420630064D0674064A06630659067F063...' (with hidden window)