Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'exexc9' = '%TEMP%\RarSFX0\a.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'word9' = '%TEMP%\RarSFX0\1\a.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'takmgr5' = '%TEMP%\RarSFX0\takmgr.exe'
- Registry Editor (RegEdit)
- '%WINDIR%\syswow64\taskkill.exe' /F /im a.exe
- %TEMP%\rarsfx1\0.exe
- %TEMP%\rarsfx3\mfc43.dll
- %TEMP%\rarsfx3\mfc42.dll
- %TEMP%\rarsfx3\mfc41.dll
- %TEMP%\rarsfx3\mfc40.dll
- %TEMP%\rarsfx2\interop.shdocvw.dll
- %TEMP%\rarsfx2\iexplore.exe
- %TEMP%\rarsfx0\1\a.exe
- %TEMP%\rarsfx3\mfc44.dll
- %TEMP%\rarsfx0\takmgr.exe
- %TEMP%\rarsfx0\0.exe
- %TEMP%\ycmxzinsgo.dll
- %TEMP%\sojyiazogadbdxtnpckc.dll
- %TEMP%\ggyqfcgvarznwymltwpw.dll
- %TEMP%\test.dat
- %TEMP%\rarsfx1\2.exe
- %TEMP%\rarsfx1\1.exe
- %TEMP%\rarsfx0\a.exe
- %TEMP%\rarsfx3\iexplore.exe
- %TEMP%\rarsfx1\0.exe
- %TEMP%\rarsfx1\1.exe
- %TEMP%\rarsfx1\2.exe
- %TEMP%\test.dat
- %TEMP%\test.dat
- 'ku##er.com':80
- 'fo###.gstatic.com':443
- 'st###c.sh.st':80
- 'go#####agmanager.com':443
- 'aj##.#oogleapis.com':443
- 'st###.#.doubleclick.net':443
- 'd1#######ny5s4.cloudfront.net':80
- 'microsoft.com':80
- 'aj##.#oogleapis.com':80
- 'fo###.#oogleapis.com':443
- 'ne###lro.net':80
- 'fa###cew.com':80
- 'li###games.com':80
- 'ge##yy.com':80
- 'fu###rom.com':80
- 'go#####analytics.com':80
- 'js#####t.newrelic.com':443
- http://ku##er.com/m17games/?
- http://cd#.##exulro.net/static/js/view118_bidshow.js
- http://ne###lro.net/js/display.js
- http://www.go#####analytics.com/ga.js
- http://cd#.##exulro.net/static/image/logo_fb2.png
- http://cd#.##exulro.net/static/image/ad_top_bg2.png?&a########
- http://cd#.##exulro.net/static/image/ahl6532.gif
- http://cd#.##exulro.net/static/image/spinner.gif
- http://cd#.##exulro.net/static/image/skip_ad/en_tran.png
- http://www.go#####analytics.com/r/__utm.gif?ut###################################################################################################################################################...
- http://cd#.##exulro.net/static/image/d_top_bg.png
- http://cd#.##exulro.net/static/image/delete2.png
- http://www.go#####analytics.com/__utm.gif?ut#####################################################################################################################################################...
- http://cd#.##exulro.net/static/image/d_bottom_bg2.png
- http://ku##er.com/SoftUpdate2//mfc42.dll
- http://ge##yy.com/bundles/advertisement/img/tracking.gif?te###########################################
- http://ge##yy.com/bundles/smeweb/img/advertisement-tracking-11188492.gif?t=##########
- http://st###c.sh.st/b5/4c/45/48/be/0d/ca/35/64/1c/e2/75/9d/8f/9e/2c/logo1707.png?20##########
- http://st###c.sh.st/js/packed/interstitial-page.js?20##########
- http://ge##yy.com/bundles/smeweb/img/tracking-11188492.gif?t=##########
- http://cd#.##exulro.net/static/js/amvn.js
- http://st###c.sh.st/bundles/smeweb/img/widget-sprite.png?20##########
- http://d1#######ny5s4.cloudfront.net/?hb##########
- http://cd#.##exulro.net/static/js/main.js?v=##########
- http://ku##er.com/m18games/?
- http://ku##er.com/m19games/?
- http://ku##er.com/m20games/?
- http://ku##er.com/m22games/?
- http://ku##er.com/m23games/?
- http://ku##er.com/m21games/?
- http://ku##er.com/m24games/?
- http://fu###rom.com/3RX37?U8#####
- http://fu###rom.com/3RX4e?Bk######
- http://ge##yy.com/epcLL8?VR######
- http://ge##yy.com/epcLCI?MX#######
- http://li###games.com/yt7/?37#####
- http://fa###cew.com/m5b?uC######
- http://ge##yy.com/epcL30?9k#######
- http://ne###lro.net/-89918ONZY/3RX37?rn#########################
- http://ne###lro.net/-89918KAUN/3RX4e?rn#########################
- http://www.go#####analytics.com/analytics.js
- http://ne###lro.net/-116775XPLG/m5b?rn#########################
- http://aj##.#oogleapis.com/ajax/libs/jquery/1.7.1/jquery.min.js
- http://cd#.##exulro.net/static/css/adfly_7.css
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- 'fo###.#oogleapis.com':443
- 'st###.#.doubleclick.net':443
- 'go#####agmanager.com':443
- 'fo###.gstatic.com':443
- 'js#####t.newrelic.com':443
- DNS ASK ku##er.com
- DNS ASK fo###.gstatic.com
- DNS ASK st###c.sh.st
- DNS ASK go#####agmanager.com
- DNS ASK st###.#.doubleclick.net
- DNS ASK cd#.##exulro.net
- DNS ASK d1#######ny5s4.cloudfront.net
- DNS ASK microsoft.com
- DNS ASK aj##.#oogleapis.com
- DNS ASK fo###.#oogleapis.com
- DNS ASK ne###lro.net
- DNS ASK fa###cew.com
- DNS ASK ge##yy.com
- DNS ASK li###games.com
- DNS ASK fu###rom.com
- DNS ASK go#####analytics.com
- DNS ASK js#####t.newrelic.com
- ClassName: 'EDIT' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%TEMP%\rarsfx1\0.exe'
- '%TEMP%\rarsfx1\1.exe'
- '%TEMP%\rarsfx1\2.exe'
- '%TEMP%\rarsfx0\0.exe'
- '%TEMP%\rarsfx0\1\a.exe'
- '%TEMP%\rarsfx0\a.exe'
- '%TEMP%\rarsfx0\takmgr.exe'
- '%TEMP%\rarsfx3\iexplore.exe'
- '%TEMP%\rarsfx2\iexplore.exe'
- '%WINDIR%\syswow64\cmd.exe'