Technical Information
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
- %APPDATA%\23EF5514-3059-436F-A4A7-4CEFAAB20EB1\run.dat
- %TEMP%\HOOHMC.pdf
- %TEMP%\aut1.tmp
- %TEMP%\aut1.tmp
- 'ti###fresh.tk':1177
- DNS ASK ti###fresh.tk
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\shell32.dll,OpenAs_RunDLL %TEMP%\HOOHMC.pdf
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe'