Technical Information
- %WINDIR%\runn\windowstask.exe
- %WINDIR%\runn\duilib_u.dll
- %WINDIR%\runn\sqlite3.dll
- %WINDIR%\runn\yloux.exe
- %WINDIR%\runn\1.bin
- %LOCALAPPDATA%\{d8270258-91d3-4f25-b697-3b77ce9150b8}\windowstask.lnk
- %TEMP%\{1712c8cf-3380-49aa-a9e7-82a8449e09a1}.exe
- %TEMP%\{60372fa9-92d6-4bb1-858d-822e14eec15d}
- %TEMP%\hi-013{d0fc8f70-e6d3-4189-8046-43688e2df7aa}\{23f4d5a9-1d96-44f6-95b1-d268a7c52fea}.lnk
- %TEMP%\regworkshop.ini
- %TEMP%\hi-013{d0fc8f70-e6d3-4189-8046-43688e2df7aa}\{23f4d5a9-1d96-44f6-95b1-d268a7c52fea}.lnk
- %TEMP%\{1712c8cf-3380-49aa-a9e7-82a8449e09a1}.exe
- %TEMP%\{60372fa9-92d6-4bb1-858d-822e14eec15d}
- '38.#4.25.23':80
- '38.##.204.65':53261
- '45.##2.205.101':15746
- http://38.##.204.65:53261/VSaySomething.exe via 38.##.204.65
- '45.##2.205.101':15746
- '<LOCALNET>.1.2':6341
- '%WINDIR%\runn\yloux.exe'
- '%TEMP%\{1712c8cf-3380-49aa-a9e7-82a8449e09a1}.exe' /s "%TEMP%\\{60372FA9-92D6-4bb1-858D-822E14EEC15D}"
- '%WINDIR%\runn\yloux.exe' ' (with hidden window)