Technical Information
- <SYSTEM32>\at.exe 00:55 /every:m,t,w,th,f,s,su ""%PROGRAM_FILES%\USER-4BB09A9C02000000000000.exe""
- <SYSTEM32>\at.exe 01:00 /every:m,t,w,th,f,s,su ""%PROGRAM_FILES%\USER-4BB09A9C02000000000000.exe""
- <SYSTEM32>\at.exe 00:45 /every:m,t,w,th,f,s,su ""%PROGRAM_FILES%\USER-4BB09A9C02000000000000.exe""
- <SYSTEM32>\at.exe 00:50 /every:m,t,w,th,f,s,su ""%PROGRAM_FILES%\USER-4BB09A9C02000000000000.exe""
- <SYSTEM32>\at.exe 01:05 /every:m,t,w,th,f,s,su ""%PROGRAM_FILES%\USER-4BB09A9C02000000000000.exe""
- <SYSTEM32>\at.exe 01:20 /every:m,t,w,th,f,s,su ""%PROGRAM_FILES%\USER-4BB09A9C02000000000000.exe""
- <SYSTEM32>\at.exe 01:25 /every:m,t,w,th,f,s,su ""%PROGRAM_FILES%\USER-4BB09A9C02000000000000.exe""
- <SYSTEM32>\at.exe 01:10 /every:m,t,w,th,f,s,su ""%PROGRAM_FILES%\USER-4BB09A9C02000000000000.exe""
- <SYSTEM32>\at.exe 01:15 /every:m,t,w,th,f,s,su ""%PROGRAM_FILES%\USER-4BB09A9C02000000000000.exe""
- <SYSTEM32>\at.exe 00:40 /every:m,t,w,th,f,s,su ""%PROGRAM_FILES%\USER-4BB09A9C02000000000000.exe""
- <SYSTEM32>\at.exe 00:05 /every:m,t,w,th,f,s,su ""%PROGRAM_FILES%\USER-4BB09A9C02000000000000.exe""
- <SYSTEM32>\at.exe 00:10 /every:m,t,w,th,f,s,su ""%PROGRAM_FILES%\USER-4BB09A9C02000000000000.exe""
- <SYSTEM32>\wscript.exe ""%PROGRAM_FILES%\USER-4BB09A9C02000000000000.vbs"" 0
- <SYSTEM32>\at.exe 00:00 /every:m,t,w,th,f,s,su ""%PROGRAM_FILES%\USER-4BB09A9C02000000000000.exe""
- <SYSTEM32>\at.exe 00:15 /every:m,t,w,th,f,s,su ""%PROGRAM_FILES%\USER-4BB09A9C02000000000000.exe""
- <SYSTEM32>\at.exe 00:30 /every:m,t,w,th,f,s,su ""%PROGRAM_FILES%\USER-4BB09A9C02000000000000.exe""
- <SYSTEM32>\at.exe 00:35 /every:m,t,w,th,f,s,su ""%PROGRAM_FILES%\USER-4BB09A9C02000000000000.exe""
- <SYSTEM32>\at.exe 00:20 /every:m,t,w,th,f,s,su ""%PROGRAM_FILES%\USER-4BB09A9C02000000000000.exe""
- <SYSTEM32>\at.exe 00:25 /every:m,t,w,th,f,s,su ""%PROGRAM_FILES%\USER-4BB09A9C02000000000000.exe""
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\tj[1].asp
- %PROGRAM_FILES%\USER-4BB09A9C02000000000000.s
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\ULU3YH2D\cs[1].asp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\cs[1].asp
- %PROGRAM_FILES%\USER-4BB09A9C02000000000000.exe
- %PROGRAM_FILES%\USER-4BB09A9C02000000000000.t
- %PROGRAM_FILES%\USER-4BB09A9C02000000000000.bat
- %PROGRAM_FILES%\USER-4BB09A9C02000000000000.vbs
- 'www.78##s.info':80
- 'www.pm##9.info':80
- 'localhost':1034
- www.pm##9.info/xztj/cs.asp
- www.78##s.info/xztj1/cs.asp?id############################
- www.pm##9.info/tj.asp?id############################
- DNS ASK www.78##s.info
- DNS ASK www.pm##9.info
- '<Private IP address>':1035