Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\bitcee3.tmp
- %WINDIR%\tasks\sdbinst.job
- <SYSTEM32>\tasks\sdbinst
- %WINDIR%\syswow64\cmd.exe
- %TEMP%\nsw5dd9.tmp
- %APPDATA%\adobe\logtransport2\bitc8ab.tmp
- %TEMP%\trucekyu.dll
- %TEMP%\simpshanghai
- %TEMP%\aspdnsfgateways\la\form\wfprocess.xml
- %TEMP%\aspdnsfgateways\la\form\x.stl-binary.xml
- %APPDATA%\encryption\mp3s\httpdocs\org.freedesktop.fwupd.remotes.lvfs-testing.metainfo.xml
- %APPDATA%\encryption\mp3s\httpdocs\vjscsvr.exe
- %APPDATA%\encryption\mp3s\httpdocs\booksschema.xml
- %APPDATA%\changelog\83.opends60.dll
- %APPDATA%\changelog\org.gnome.simplescan.gschema.xml
- %APPDATA%\changelog\jbimpui.dll
- %APPDATA%\changelog\custsat.dll
- %APPDATA%\changelog\metade.dll
- %APPDATA%\changelog\x-pem-key.xml
- %APPDATA%\changelog\com.ubuntu.softwareproperties.gschema.xml
- %TEMP%\972298ba.lnk
- %APPDATA%\system\logs.dat
- %APPDATA%\adobe\logtransport2\bitc8ab.tmp
- %APPDATA%\microsoft\windows\start menu\programs\startup\bitcee3.tmp
- from %APPDATA%\adobe\logtransport2\bitc8ab.tmp to %APPDATA%\adobe\logtransport2\sdbinst.exe
- 'do######ck2091.duckdns.org':9593
- DNS ASK do######ck2091.duckdns.org
- '%WINDIR%\syswow64\rundll32.exe' TruceKyu,Assignats
- '%WINDIR%\syswow64\cmd.exe'