Technical Information
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'system' = '%WINDIR%\system.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'sms' = '%WINDIR%\sms.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'alg' = '%WINDIR%\alg.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'wdmon' = '%WINDIR%\wdmon.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'vlc' = '%WINDIR%\vlc.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'servicelayer' = '%WINDIR%\servicelayer.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'netx' = '%WINDIR%\svx.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'netw' = '%WINDIR%\svw.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'netc' = '%WINDIR%\svc.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'lsass' = '%WINDIR%\lsass.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'amoumain' = '%WINDIR%\amoumain.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'ctfmon' = '%WINDIR%\ctfmon.exe'
- mailslot\123
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\q1e129qo\bullet[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\httperrorpagesscripts[2]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\info_48[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bg0n0zou\background_gradient[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\httperrorpagesscripts[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\errorpagestrings[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\down[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\down[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bg0n0zou\dnserrordiagoff_weboc[2]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bg0n0zou\dnserrordiagoff_weboc[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\bullet[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\q1e129qo\info_48[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\background_gradient[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bg0n0zou\httperrorpagesscripts[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\errorpagetemplate[1]
- %LOCALAPPDATA%\microsoft\internet explorer\msimgsiz.dat
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bg0n0zou\info_48[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\bullet[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\background_gradient[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\q1e129qo\httperrorpagesscripts[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\info_48[2]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bg0n0zou\bullet[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\background_gradient[2]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\httperrorpagesscripts[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\errorpagetemplate[2]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\q1e129qo\errorpagestrings[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\errorpagetemplate[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\q1e129qo\navcancl[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\q1e129qo\errorpagetemplate[2]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\navcancl[2]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\navcancl[1]
- %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012025042420250425\index.dat
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\q1e129qo\down[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\errorpagestrings[1]
- %LOCALAPPDATA%\microsoft\internet explorer\domstore\index.dat
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\q1e129qo\errorpagetemplate[1]
- %WINDIR%\ctfmon.exe
- %TEMP%\pinnew.exe
- %TEMP%\q1.exe
- %TEMP%\q2.exe
- %TEMP%\q3.exe
- %TEMP%\q4.exe
- %TEMP%\q5.exe
- %TEMP%\nopmulti5.exe
- %TEMP%\q6.exe
- %TEMP%\q8.exe
- %TEMP%\q9.exe
- %TEMP%\teste1_p.exe
- %TEMP%\teste2_p.exe
- %TEMP%\teste3_p.exe
- %TEMP%\teste4_p.exe
- %TEMP%\q7.exe
- %TEMP%\nopmulti3.exe
- %TEMP%\nopmulti1.exe
- %TEMP%\avto4.exe
- %WINDIR%\amoumain.exe
- %WINDIR%\lsass.exe
- %WINDIR%\svc.exe
- %WINDIR%\svw.exe
- %WINDIR%\svx.exe
- %WINDIR%\vlc.exe
- %WINDIR%\servicelayer.exe
- %WINDIR%\wdmon.exe
- %WINDIR%\alg.exe
- %WINDIR%\sms.exe
- %WINDIR%\system.exe
- %TEMP%\avto.exe
- %TEMP%\avto1.exe
- %TEMP%\avto2.exe
- %TEMP%\avto3.exe
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\dnserrordiagoff_weboc[1]
- %LOCALAPPDATA%\microsoft\internet explorer\domstore\kresl46f\www.cafebarplaza[1].xml
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\dnserrordiagoff_weboc[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\q1e129qo\navcancl[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\info_48[2]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bg0n0zou\bullet[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\background_gradient[2]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\httperrorpagesscripts[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\q1e129qo\errorpagestrings[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\bullet[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bg0n0zou\info_48[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\httperrorpagesscripts[2]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\errorpagetemplate[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\q1e129qo\errorpagetemplate[2]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\navcancl[2]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\navcancl[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\q1e129qo\background_gradient[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\down[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\info_48[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bg0n0zou\background_gradient[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\down[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\bullet[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\httperrorpagesscripts[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\q1e129qo\info_48[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\background_gradient[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bg0n0zou\httperrorpagesscripts[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\errorpagestrings[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\errorpagestrings[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\errorpagetemplate[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\q1e129qo\errorpagetemplate[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bg0n0zou\dnserrordiagoff_weboc[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\q1e129qo\bullet[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\bullet[2]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\q1e129qo\errorpagetemplate[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\errorpagestrings[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\background_gradient[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\info_48[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\errorpagestrings[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\q1e129qo\errorpagestrings[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\httperrorpagesscripts[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\httperrorpagesscripts[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\background_gradient[2]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\604pwz7f\bullet[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bg0n0zou\bullet[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dzhkzdlo\navcancl[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\q1e129qo\info_48[1]
- 'au####loaders.net':80
- 'se###pworld.cn':80
- 'gr###instant.cn':80
- 'ca###arplaza.cn':80
- 'hm.##idu.com':443
- 'pu##.###nzhang.baidu.com':80
- 'ap#.##are.baidu.com':80
- http://se###pworld.cn/incallspa.php
- http://gr###instant.cn/lafastfind.php
- http://ca###arplaza.cn/faqaboutnet.php
- http://www.ca###arplaza.cn/faqaboutnet.php
- http://www.ca###arplaza.cn/common.js
- http://www.ca###arplaza.cn/tj.js
- http://pu##.###nzhang.baidu.com/push.js
- http://ap#.##are.baidu.com/s.gif?l=##########################################
- http://gr###instant.cn/greatinstant.php
- http://gr###instant.cn/yourseekerz.php
- 'hm.##idu.com':443
- DNS ASK sa###ngins.cn
- DNS ASK au####loaders.net
- DNS ASK gr###instant.cn
- DNS ASK se###pworld.cn
- DNS ASK ca###arplaza.cn
- DNS ASK hm.##idu.com
- DNS ASK pu##.###nzhang.baidu.com
- DNS ASK ap#.##are.baidu.com
- DNS ASK tr##ublo.cn
- DNS ASK gr###tab.net
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%TEMP%\teste4_p.exe'
- '%TEMP%\avto2.exe'
- '%TEMP%\avto3.exe'
- '%TEMP%\avto4.exe'
- '%TEMP%\nopmulti1.exe'
- '%TEMP%\nopmulti3.exe'
- '%TEMP%\nopmulti5.exe'
- '%TEMP%\pinnew.exe'
- '%TEMP%\q1.exe'
- '%TEMP%\q2.exe'
- '%TEMP%\q3.exe'
- '%TEMP%\q4.exe'
- '%TEMP%\q5.exe'
- '%TEMP%\q6.exe'
- '%TEMP%\q7.exe'
- '%TEMP%\q8.exe'
- '%TEMP%\q9.exe'
- '%TEMP%\teste1_p.exe'
- '%TEMP%\teste2_p.exe'
- '%TEMP%\teste3_p.exe'
- '%TEMP%\avto1.exe'
- '%TEMP%\avto.exe'