Technical Information
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %APPDATA%\opera software\opera stable\login data
- %APPDATA%\mozilla\firefox\profiles.ini
- ClassName: 'OLLYDBG', WindowName: ''
- ClassName: 'GBDYLLO', WindowName: ''
- ClassName: 'pediy06', WindowName: ''
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: '', WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: '', WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'RegmonClass', WindowName: ''
- ClassName: '', WindowName: 'Registry Monitor - Sysinternals: www.sysinternals.com'
- %TEMP%\nde6ukgykb\5rtagg.tmp
- %TEMP%\nde6ukgykb\files_\system_info.txt
- %TEMP%\nde6ukgykb\files_\screenshot.jpg
- %TEMP%\nde6ukgykb\_files\_information.txt
- %TEMP%\nde6ukgykb\_files\_screen_desktop.jpeg
- %TEMP%\nde6ukgykb\files_\cookies\mozilla_firefox.txt
- %TEMP%\nde6ukgykb\_files\_cookies\mozilla_firefox.txt
- %TEMP%\nde6ukgykb\c5jmn.tmp-shm
- %TEMP%\nde6ukgykb\files_\forms.txt
- %TEMP%\nde6ukgykb\_files\_allforms_list.txt
- %TEMP%\nde6ukgykb\fehs8.tmp
- %TEMP%\nde6ukgykb\c5jmn.tmp
- %TEMP%\nde6ukgykb\files_\cookies\opera.txt
- %TEMP%\nde6ukgykb\_files\_cookies\opera.txt
- %TEMP%\nde6ukgykb\ky4rajcjr5ybq.zip
- %TEMP%\nde6ukgykb\qww1c.tmp
- %TEMP%\nde6ukgykb\apyte.tmp
- %TEMP%\nde6ukgykb\files_\cookies.txt
- %TEMP%\nde6ukgykb\_files\_allcookies_list.txt
- %TEMP%\nde6ukgykb\files_\cookies\google_chrome.txt
- %TEMP%\nde6ukgykb\_files\_cookies\google_chrome.txt
- %TEMP%\nde6ukgykb\sqbt.tmp
- %TEMP%\nde6ukgykb\rh6jee.tmp
- %TEMP%\nde6ukgykb\vfki2u.tmp
- %TEMP%\nde6ukgykb\xtvy.tmp
- %TEMP%\nde6ukgykb\lvuzi.tmp
- %TEMP%\nde6ukgykb\5fzpnj.tmp
- %TEMP%\nde6ukgykb\yqufw.tmp
- %TEMP%\nde6ukgykb\ueu2js.tmp
- %TEMP%\nde6ukgykb\sw3l.tmp
- %TEMP%\nde6ukgykb\6crjekolz2ee.zip
- %TEMP%\nde6ukgykb\c5jmn.tmp-shm
- %TEMP%\nde6ukgykb\xtvy.tmp
- %TEMP%\nde6ukgykb\vfki2u.tmp
- %TEMP%\nde6ukgykb\ueu2js.tmp
- %TEMP%\nde6ukgykb\sw3l.tmp
- %TEMP%\nde6ukgykb\sqbt.tmp
- %TEMP%\nde6ukgykb\rh6jee.tmp
- %TEMP%\nde6ukgykb\qww1c.tmp
- %TEMP%\nde6ukgykb\yqufw.tmp
- %TEMP%\nde6ukgykb\lvuzi.tmp
- %TEMP%\nde6ukgykb\files_\cookies.txt
- %TEMP%\nde6ukgykb\files_\cookies\opera.txt
- %TEMP%\nde6ukgykb\fehs8.tmp
- %TEMP%\nde6ukgykb\c5jmn.tmp
- %TEMP%\nde6ukgykb\apyte.tmp
- %TEMP%\nde6ukgykb\5rtagg.tmp
- %TEMP%\nde6ukgykb\5fzpnj.tmp
- %TEMP%\nde6ukgykb\files_\forms.txt
- %TEMP%\nde6ukgykb\_files\_cookies\opera.txt
- 'bi###ene02.top':80
- 'mo###ss05.top':80
- http://bi###ene02.top/index.php
- http://mo###ss05.top/index.php
- DNS ASK bi###ene02.top
- DNS ASK mo###ss05.top
- ClassName: '18467-41' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c rd /s /q %TEMP%\NDe6ukGykB & timeout 2 & del /f /q "<Full path to file>"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c rd /s /q %TEMP%\NDe6ukGykB & timeout 2 & del /f /q "<Full path to file>"
- '%WINDIR%\syswow64\timeout.exe' 2