Technical Information
- [<HKLM>\System\CurrentControlSet\Services\abc2.0] 'ImagePath' = '%TEMP%\~abcwZfEs.sys'
- [<HKLM>\System\CurrentControlSet\Services\abc2.0] 'ImagePath' = '%TEMP%\~abcnnWOc.sys'
- [<HKLM>\System\CurrentControlSet\Services\abc2.0] 'ImagePath' = '%TEMP%\~abcmyGL5.sys'
- [<HKLM>\System\CurrentControlSet\Services\abc2.0] 'ImagePath' = '%TEMP%\~abcXeqbG.sys'
- 'abc2.0' %TEMP%\~abcwZfEs.sys
- 'abc2.0' %TEMP%\~abcnnWOc.sys
- 'abc2.0' %TEMP%\~abcmyGL5.sys
- 'abc2.0' %TEMP%\~abcXeqbG.sys
- %TEMP%\~abcwZfEs.sys
- %WINDIR%\temp\udd842c.tmp
- %TEMP%\~abcnnWOc.sys
- %TEMP%\9d178kw84oa.exe
- %TEMP%\~abcmyGL5.sys
- %TEMP%\~abcXeqbG.sys
- %APPDATA%\microsoft\internet explorer\userdata\index.dat
- %APPDATA%\microsoft\internet explorer\userdata\h8j67wy6\userdatabidupsid[1].xml
- %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012020102020201021\index.dat
- %APPDATA%\microsoft\internet explorer\userdata\vo762sq0\oxmlstore[1].xml
- %TEMP%\~abcwZfEs.sys
- %TEMP%\~abcnnWOc.sys
- %TEMP%\~abcmyGL5.sys
- %TEMP%\~abcXeqbG.sys
- %WINDIR%\temp\udd842c.tmp
- %TEMP%\~abcwZfEs.sys
- %TEMP%\~abcnnWOc.sys
- %TEMP%\~abcmyGL5.sys
- %TEMP%\~abcXeqbG.sys
- http://do#####d.kulove123.com/tcgg.txt
- DNS ASK do#####d.kulove123.com
- DNS ASK ba##u.com
- DNS ASK microsoft.com
- DNS ASK m.##idu.com
- DNS ASK ds##.#dstatic.com
- DNS ASK sp#.#aidu.com
- DNS ASK he#####tatic.baidu.com
- DNS ASK ss#.##static.com
- ClassName: '' WindowName: 'Microsoft Internet Explorer'
- ClassName: 'DDEMLMom' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: '' WindowName: 'TPHelper.exe'
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%TEMP%\9d178kw84oa.exe'