Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'UnLoad_TorProject' = '%APPDATA%\Microsoft Update\UnLoad.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'TorProject' = '%APPDATA%\Tor Project\tor.exe'
- %HOMEPATH%\Start Menu\Programs\Startup\SystemAutorun.exe
- [<HKLM>\SYSTEM\ControlSet001\Services\NetDDEdsdm] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\NetDDEdsdm] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\NetDDEdsdm] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\NetDDE] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\NetDDE] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\NetDDE] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\RDSessMgr] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\RDSessMgr] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\RDSessMgr] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\NetTcpPortSharing] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\NetTcpPortSharing] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\NetTcpPortSharing] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\ImapiService] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\ImapiService] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\ImapiService] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\idsvc] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\idsvc] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\idsvc] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\MSIServer] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\MSIServer] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\MSIServer] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\mnmsrvc] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\mnmsrvc] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\mnmsrvc] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\VSS] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\VSS] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\VSS] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\UPS] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\UPS] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\UPS] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\WPFFontCache_v0400] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\WPFFontCache_v0400] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\WPFFontCache_v0400] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\WmiApSrv] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\WmiApSrv] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\WmiApSrv] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\SCardSvr] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\SCardSvr] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\SCardSvr] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\RSVP] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\RSVP] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\RSVP] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\TlntSvr] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\TlntSvr] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\TlntSvr] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\SysmonLog] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\SysmonLog] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\SysmonLog] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\rpcapd] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\rpcapd] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\rpcapd] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\QQPCRTP] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\QQPCRTP] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\QQPCRTP] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\TAOFrame] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\TAOFrame] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\TAOFrame] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\RsMgrSvc] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\RsMgrSvc] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\RsMgrSvc] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\BDKVRTP] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\BDKVRTP] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\BDKVRTP] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\BaiduHips] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\BaiduHips] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\BaiduHips] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\Defense] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\Defense] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\Defense] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\BDMRTP] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\BDMRTP] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\BDMRTP] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\clr_optimization_v4.0.30319_32] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\clr_optimization_v4.0.30319_32] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\clr_optimization_v4.0.30319_32] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\clr_optimization_v2.0.50727_32] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\clr_optimization_v2.0.50727_32] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\clr_optimization_v2.0.50727_32] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\FontCache3.0.0.0] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\FontCache3.0.0.0] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\FontCache3.0.0.0] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\dmadmin] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\dmadmin] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\dmadmin] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\aspnet_state] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\aspnet_state] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\aspnet_state] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\QQPMAndroidServer] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\QQPMAndroidServer] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\QQPMAndroidServer] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\ClipSrv] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\ClipSrv] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\ClipSrv] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\CiSvc] 'Start' = '00000001'
- [<HKLM>\SOFTWARE\Classes\SYSTEM\CurrentControlSet\Services\CiSvc] 'Start' = '00000001'
- [<HKCU>\SYSTEM\CurrentControlSet\Services\CiSvc] 'Start' = '00000001'
- '%APPDATA%\AntiSpy.exe'
- '%APPDATA%\icub.exe'
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES2.tmp" "%TEMP%\CSC1.tmp"
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\hasosgfr.cmdline"
- safari.exe
- iexplore.exe
- firefox.exe
- chrome.exe
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'ProxyServer' = ''
- [<HKLM>\SOFTWARE\Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'ProxyServer' = ''
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings] 'ProxyServer' = ''
- %APPDATA%\Microsoft Update\UnLoad.exe
- %APPDATA%\icub.exe
- %APPDATA%\AntiSpy.exe
- %APPDATA%\LiteDB\ppiName.xml
- %APPDATA%\LiteDB\UnicKey.xml
- %TEMP%\hasosgfr.dll
- %TEMP%\hasosgfr.cmdline
- %TEMP%\hasosgfr.0.cs
- %TEMP%\hasosgfr.out
- %TEMP%\RES2.tmp
- %TEMP%\CSC1.tmp
- %TEMP%\hasosgfr.out
- %TEMP%\hasosgfr.0.cs
- %TEMP%\hasosgfr.cmdline
- %TEMP%\RES2.tmp
- %TEMP%\CSC1.tmp
- %TEMP%\hasosgfr.dll
- 'ss###anager.com':80
- 'wp#d':80
- ss###anager.com/api/msgStatus/?da######################
- wp#d/wpad.dat
- DNS ASK ss###anager.com
- DNS ASK wp#d
- ClassName: 'Indicator' WindowName: ''