Technical Information
- %WINDIR%\explorer.exe
- firefox.exe
- %TEMP%\nsudb.tmp
- %TEMP%\otopwf.x
- %TEMP%\nsz149.tmp\qnnviwz.dll
- 'sc###thny.com':80
- http://www.sc###thny.com/k13s/?DL##################################################################################
- DNS ASK sc###thny.com
- '%WINDIR%\syswow64\raserver.exe'
- '%WINDIR%\syswow64\cmd.exe' del "<Full path to file>"