Technical Information
- %HOMEPATH%\Start Menu\Programs\Startup\890207d7-2112-4788-8692-49ab13a2592f.vbs
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\viddgtix.cmdline"
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES6.tmp" "%TEMP%\CSC5.tmp"
- '<SYSTEM32>\wscript.exe' "%HOMEPATH%\Start Menu\Programs\Startup\890207d7-2112-4788-8692-49ab13a2592f.vbs"
- '%ALLUSERSPROFILE%\Application Data\vssagent.exe'
- %TEMP%\nsv4.tmp\ckrtzyxw.yev
- %TEMP%\nsv4.tmp\feYIfGUcPbT.dll
- %TEMP%\nsv4.tmp\System.dll
- %TEMP%\nsv4.tmp\csqs5bk2.cvi
- %TEMP%\nsv4.tmp\CLR.dll
- %TEMP%\nsv4.tmp\vchord-f.mp3
- %TEMP%\nsv4.tmp\ni5th7nz.txt
- %ALLUSERSPROFILE%\Application Data\vssagent.exe
- %TEMP%\nsr2.tmp\ckrtzyxw.yev
- %TEMP%\nsr2.tmp\feYIfGUcPbT.dll
- %TEMP%\nsr2.tmp\System.dll
- %TEMP%\nsr2.tmp\csqs5bk2.cvi
- %TEMP%\nsr2.tmp\CLR.dll
- %TEMP%\nsr2.tmp\vchord-f.mp3
- %TEMP%\nsr2.tmp\ni5th7nz.txt
- %TEMP%\viddgtix.out
- %TEMP%\viddgtix.cmdline
- %TEMP%\viddgtix.dll
- %TEMP%\RES6.tmp
- %TEMP%\CSC5.tmp
- %TEMP%\viddgtix.0.cs
- 'fr####y.nostyle.pw':1998
- DNS ASK fr####y.nostyle.pw
- ClassName: 'Shell_TrayWnd' WindowName: ''