Technical Information
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'Synaptics Pointing Device Driver' = '%PROGRAMDATA%\Synaptics\Synaptics.exe'
- %HOMEPATH%\downloads\chromesetup.exe
- %HOMEPATH%\downloads\icq_rfrset.exe
- %HOMEPATH%\downloads\k-lite_codec_pack_1110_mega.exe
- %HOMEPATH%\downloads\k-lite_codec_pack_1110_mega_dlm.exe
- %HOMEPATH%\downloads\magent_rfrset.exe
- %HOMEPATH%\downloads\mirc741.exe
- %HOMEPATH%\downloads\opera_ni_stable.exe
- %HOMEPATH%\downloads\pidgin-2.10.11.exe
- %HOMEPATH%\downloads\steamsetup.exe
- %HOMEPATH%\downloads\thunderbird setup 31.6.0.exe
- %HOMEPATH%\downloads\winamp5666_full_all.exe
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%PROGRAMDATA%\server.exe" "server.exe" ENABLE
- synaptics.exe
- <Current directory>\._cache_<File name>.exe
- %TEMP%\rcxac4a.tmp
- %TEMP%\onebjhps.exe
- %TEMP%\rcxae01.tmp
- %TEMP%\onebjhps.ico
- %TEMP%\rcxae7f.tmp
- %TEMP%\aqqodsz7.exe
- %TEMP%\rcxb0f1.tmp
- %TEMP%\aqqodsz7.ico
- %TEMP%\rcxab30.tmp
- %TEMP%\rizz4zcx.ico
- %TEMP%\rcxb344.tmp
- %TEMP%\vf1sjfzo.ico
- %TEMP%\rcxb857.tmp
- %TEMP%\pzanu9zz.exe
- %TEMP%\rcxbe72.tmp
- %TEMP%\pzanu9zz.ico
- %TEMP%\rcxcb15.tmp
- %TEMP%\nxhccaju.exe
- %TEMP%\rcxdcf9.tmp
- %TEMP%\vf1sjfzo.exe
- %TEMP%\rcxb7c9.tmp
- %TEMP%\rizz4zcx.exe
- %TEMP%\rcx8f1c.tmp
- %TEMP%\bjx5eb9m.ico
- <Current directory>\._cache_synaptics.exe
- %TEMP%\v5iqsga1.exe
- %TEMP%\rcx31df.tmp
- %TEMP%\v5iqsga1.ico
- %TEMP%\rcx324e.tmp
- %TEMP%\xcs9z4pf.exe
- %TEMP%\rcx3954.tmp
- %TEMP%\xcs9z4pf.ico
- %TEMP%\rcx4319.tmp
- %PROGRAMDATA%\synaptics\synaptics.exe
- %TEMP%\mcn555kb.exe
- %TEMP%\mcn555kb.ico
- %TEMP%\rcx5e92.tmp
- %PROGRAMDATA%\server.exe
- %TEMP%\9pvnibpd.exe
- %TEMP%\rcx7c5c.tmp
- %TEMP%\9pvnibpd.ico
- %TEMP%\rcx7ce9.tmp
- %TEMP%\bjx5eb9m.exe
- %TEMP%\rcx841e.tmp
- %TEMP%\rcx5673.tmp
- %TEMP%\nxhccaju.ico
- %TEMP%\rcxe1bc.tmp
- <Current directory>\._cache_<File name>.exe
- %PROGRAMDATA%\synaptics\synaptics.exe
- <Current directory>\._cache_synaptics.exe
- %TEMP%\v5iqsga1.exe
- %TEMP%\pzanu9zz.ico
- %TEMP%\pzanu9zz.exe
- %TEMP%\vf1sjfzo.ico
- %TEMP%\vf1sjfzo.exe
- %TEMP%\aqqodsz7.ico
- %TEMP%\aqqodsz7.exe
- %TEMP%\onebjhps.ico
- %TEMP%\onebjhps.exe
- %TEMP%\rizz4zcx.ico
- %TEMP%\rizz4zcx.exe
- %TEMP%\bjx5eb9m.ico
- %TEMP%\bjx5eb9m.exe
- %TEMP%\9pvnibpd.ico
- %TEMP%\9pvnibpd.exe
- %TEMP%\mcn555kb.ico
- %TEMP%\mcn555kb.exe
- %TEMP%\xcs9z4pf.ico
- %TEMP%\xcs9z4pf.exe
- %TEMP%\v5iqsga1.ico
- %TEMP%\nxhccaju.exe
- %TEMP%\nxhccaju.ico
- from %TEMP%\rcx31df.tmp to %TEMP%\v5iqsga1.exe
- from %TEMP%\rcxcb15.tmp to %TEMP%\pzanu9zz.exe
- from %TEMP%\rcxbe72.tmp to %TEMP%\pzanu9zz.exe
- from %TEMP%\rcxb857.tmp to %TEMP%\vf1sjfzo.exe
- from %TEMP%\rcxb7c9.tmp to %TEMP%\vf1sjfzo.exe
- from %TEMP%\rcxb344.tmp to %TEMP%\aqqodsz7.exe
- from %TEMP%\rcxb0f1.tmp to %TEMP%\aqqodsz7.exe
- from %TEMP%\rcxae7f.tmp to %TEMP%\onebjhps.exe
- from %TEMP%\rcxae01.tmp to %TEMP%\onebjhps.exe
- from %TEMP%\rcxac4a.tmp to %TEMP%\rizz4zcx.exe
- from %TEMP%\rcxab30.tmp to %TEMP%\rizz4zcx.exe
- from %TEMP%\rcx8f1c.tmp to %TEMP%\bjx5eb9m.exe
- from %TEMP%\rcx841e.tmp to %TEMP%\bjx5eb9m.exe
- from %TEMP%\rcx7ce9.tmp to %TEMP%\9pvnibpd.exe
- from %TEMP%\rcx7c5c.tmp to %TEMP%\9pvnibpd.exe
- from %TEMP%\rcx5e92.tmp to %TEMP%\mcn555kb.exe
- from %TEMP%\rcx5673.tmp to %TEMP%\mcn555kb.exe
- from %TEMP%\rcx4319.tmp to %TEMP%\xcs9z4pf.exe
- from %TEMP%\rcx3954.tmp to %TEMP%\xcs9z4pf.exe
- from %TEMP%\rcx324e.tmp to %TEMP%\v5iqsga1.exe
- from %TEMP%\rcxdcf9.tmp to %TEMP%\nxhccaju.exe
- from %TEMP%\rcxe1bc.tmp to %TEMP%\nxhccaju.exe
- 'xr##.mooo.com':1199
- 'aq###1.kro.kr':2016
- http://fr####s.afraid.org/api/?ac###########################################################
- DNS ASK xr##.mooo.com
- DNS ASK aq###1.kro.kr
- DNS ASK fr####s.afraid.org
- ClassName: 'MS_WINHELP' WindowName: ''
- '<Current directory>\._cache_<File name>.exe'
- '%PROGRAMDATA%\synaptics\synaptics.exe' InjUpdate
- '%PROGRAMDATA%\synaptics\synaptics.exe'
- '<Current directory>\._cache_synaptics.exe'
- '%PROGRAMDATA%\server.exe'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%PROGRAMDATA%\server.exe" "server.exe" ENABLE' (with hidden window)