Technical Information
- User Account Control (UAC)
- %TEMP%\rarsfx0\2d easy downloader.exe
- %TEMP%\rarsfx0\dog.dll
- %TEMP%\rarsfx0\fig.dll
- %TEMP%\rarsfx0\log.dll
- %TEMP%\rarsfx0\ofg.dll
- %TEMP%\rarsfx0\ofgn.dll
- %TEMP%\rarsfx0\prg.dll
- %TEMP%\rarsfx0\stg.dll
- %TEMP%\rarsfx0\strg.dll
- %TEMP%\rarsfx0\did.cpx
- %TEMP%\aut62dc.tmp
- %TEMP%\hidwwma
- %TEMP%\rarsfx0\er.exe
- %TEMP%\aut6647.tmp
- %TEMP%\uwwvsjl
- %LOCALAPPDATA%\microsoft\internet explorer\msimgsiz.dat
- %TEMP%\aut62dc.tmp
- %TEMP%\hidwwma
- %TEMP%\aut6647.tmp
- %TEMP%\uwwvsjl
- '2d###loadz.com':80
- http://www.2d###loadz.com/om/get_data_3.php?os######################################
- DNS ASK 2d###loadz.com
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%TEMP%\rarsfx0\2d easy downloader.exe'
- '%TEMP%\rarsfx0\er.exe' *
- '%WINDIR%\syswow64\cmd.exe' /c rasdial
- '%WINDIR%\syswow64\rasdial.exe'
- '%WINDIR%\syswow64\cmd.exe' /c rasdial' (with hidden window)