Technical Information
- %WINDIR%\explorer.exe
- %TEMP%\nsm55ed.tmp\ymvkl8s8.dll
- 'ga###te.space':80
- 'wa#####toproducts.com':80
- DNS ASK fo######tables-chairs.com
- DNS ASK ga###te.space
- DNS ASK wa#####toproducts.com
- DNS ASK to###ndgear.com
- '%WINDIR%\syswow64\wlanext.exe'
- '%WINDIR%\syswow64\cmd.exe' del "<Full path to file>"