Technical Information
- '<SYSTEM32>\rundll32.exe' "%TEMP%\ins1.tmp",gugsaxfq install
- <Full path to virus>
- %TEMP%\ins1.tmp
- 'wm###on.ce.ms':80
- wm###on.ce.ms/jibzbDTiquPDHywHGktC6LuTPA5xRSy8fOWJvUpX44JgYSG11/7P+r7D2IDhppnqan3Cpove0PJsvSFWrnGoRmpBe5OeRfN8LCa+hw8NhSrq8A==
- wm###on.ce.ms/wyJdfauB6YlhE/BxQfZVpXCvVtoYbiFBqmFnWVrudHWK/sYB3voG59/xLcZ2XaAPY3vxFgaDeLTY5GpZDCkulGpd8Vw71U804VGqZcvGeAurjtpMoO3FOgBn/msbwlDVmDqFG4Mn/c8KS8PQss+4m2DTeDbDAwBgbI02+GI5u4n7s9CpPGgITiCFxW6sSAU+4dzt1+UPpP0=
- DNS ASK wm###on.ce.ms
- ClassName: 'Shell_TrayWnd' WindowName: ''