Technical Information
- [<HKLM>\SYSTEM\CurrentControlSet\Services\8bd230ff] 'ImagePath' = '%WINDIR%\8bd230ff.sys'
- '8bd230ff' %WINDIR%\8bd230ff.sys
- %TEMP%\af42dbe70ad9f2b1.dat
- %WINDIR%\8bd230ff.sys
- %WINDIR%\temp\uddf99a.tmp
- %TEMP%\af42dbe70ad9f2b1.dat
- %WINDIR%\temp\uddf99a.tmp
- %WINDIR%\8bd230ff.sys
- 'w1.##data.net':80
- http://ha#####.blog.163.com/blog/static/2687390192018310312858/
- http://no##.youdao.com/yws/public/note/6369188ed41d8876d0a457ea5f02552c
- http://no##.youdao.com/yws/public/resource/823abcf7db12f1b106b795713d5632d0/xmlnote/908CD215A2B641468405B931343E74EA/7521
- http://12#.##.229.169:80/do.php via 12#.#1.229.169
- DNS ASK ha#####.blog.163.com
- DNS ASK no##.youdao.com
- DNS ASK w1.##data.net