Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '601091505492281409436884643734522112613252883339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe' = '%TEMP%\601091505492281409436884643734522112613252883339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\5953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\8857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\92336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\71551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\23989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\3262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\92281409436884643734522112613252883339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\409436884643734522112613252883339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\601091505492281409436884643734522112613252883339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\1505492281409436884643734522112613252883339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\6884643734522112613252883339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\2613252883339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\52883339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\43734522112613252883339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\522112613252883339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\2096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\64071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\6648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\4218061516400894517126793<Virus name>.exe'
- '%TEMP%\4517126793<Virus name>.exe'
- '%TEMP%\26793<Virus name>.exe'
- '%TEMP%\61516400894517126793<Virus name>.exe'
- '%TEMP%\400894517126793<Virus name>.exe'
- '%TEMP%\28307626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\5798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\79303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\15065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\815936912428307626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\6912428307626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\6012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe'
- '%TEMP%\95906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe'
- '<SYSTEM32>\cmd.exe' /c %HOMEPATH%\Local Settings\Tempscratch.cmd
- %TEMP%\667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\5953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\92336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\8857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\23989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\3262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\71551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\52883339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\1505492281409436884643734522112613252883339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\92281409436884643734522112613252883339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\601091505492281409436884643734522112613252883339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\img670267.912209965.jpg
- %TEMP%\aut1.tmp
- %TEMP%\522112613252883339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\2613252883339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\43734522112613252883339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\409436884643734522112613252883339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\6884643734522112613252883339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\456984218061516400894517126793<Virus name>.exe
- %TEMP%\4218061516400894517126793<Virus name>.exe
- %TEMP%\64071456984218061516400894517126793<Virus name>.exe
- %TEMP%\626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\6648664071456984218061516400894517126793<Virus name>.exe
- %HOMEPATH%\Local Settings\Tempscratch.cmd
- %TEMP%\26793<Virus name>.exe
- %TEMP%\4517126793<Virus name>.exe
- %TEMP%\61516400894517126793<Virus name>.exe
- %TEMP%\400894517126793<Virus name>.exe
- %TEMP%\28307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\5798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\79303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\2096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\15065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\6912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\95906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\6012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\5953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\71551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\8857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\92336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\2096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\23989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\3262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\409436884643734522112613252883339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\6884643734522112613252883339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\92281409436884643734522112613252883339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\aut1.tmp
- %TEMP%\1505492281409436884643734522112613252883339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\52883339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\2613252883339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\43734522112613252883339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\522112613252883339228857892336667565953571551456203262423989284172096215065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\456984218061516400894517126793<Virus name>.exe
- %TEMP%\4218061516400894517126793<Virus name>.exe
- %TEMP%\64071456984218061516400894517126793<Virus name>.exe
- %TEMP%\626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\6648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\26793<Virus name>.exe
- %HOMEPATH%\Local Settings\Tempscratch.cmd
- %TEMP%\4517126793<Virus name>.exe
- %TEMP%\61516400894517126793<Virus name>.exe
- %TEMP%\400894517126793<Virus name>.exe
- %TEMP%\79303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\5798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\15065517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\517775798979303991276012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\6912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\28307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\6012295906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- %TEMP%\95906815936912428307626106648664071456984218061516400894517126793<Virus name>.exe
- ClassName: 'Indicator' WindowName: '(null)'