Technical Information
- %APPDATA%\hftof.exe
- %TEMP%\ycmzsjdnws
- %APPDATA%\hftof.exe
- 'localhost':80
- DNS ASK au######on.whatismyip.com
- DNS ASK ju####x.cwsurf.de
- '%APPDATA%\hftof.exe' <Full path to file>
- '%APPDATA%\hftof.exe' <Full path to file>' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\dw20.exe' -x -s 948