Technical Information
- <SYSTEM32>\tasks\with elevate management productivity
- C:\users\public\documents\z9pcw\y5tlg.exe
- C:\users\public\documents\z9pcw\y5tlg.dat
- C:\users\public\documents\z9pcw\edge.xml
- C:\users\public\documents\z9pcw\edge.jpg
- %TEMP%\_ir_tu2_temp_0\_tuprojdt.dat
- %TEMP%\_ir_tu2_temp_0\irimg1.jpg
- %TEMP%\_ir_tu2_temp_0\irimg2.jpg
- %TEMP%\_ir_tu2_temp_0\irimg3.jpg
- %TEMP%\_ir_tu2_temp_0\irimg4.jpg
- %TEMP%\xshell 6 update log.txt
- C:\users\public\documents\z9pcw\bnq21.exe
- C:\users\public\documents\z9pcw\bnq21.dat
- C:\xxxx.ini
- '20#.#9.169.52':8000
- '20#.#9.169.52':7700
- http://20#.##.169.52:8000/ll-4 via 20#.#9.169.52
- http://20#.##.169.52:8000/1 via 20#.#9.169.52
- http://20#.##.169.52:8000/2 via 20#.#9.169.52
- http://20#.##.169.52:8000/3 via 20#.#9.169.52
- http://20#.##.169.52:8000/4 via 20#.#9.169.52
- '20#.#9.169.52':7700
- ClassName: 'CTXOPConntion_Class' WindowName: ''
- 'C:\users\public\documents\z9pcw\y5tlg.exe'
- 'C:\users\public\documents\z9pcw\y5tlg.exe' ' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo.>c:\xxxx.ini' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo.>c:\xxxx.ini