Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'trkcore' = '%ALLUSERSPROFILE%\Microsoft\Roaming\svchost.exe'
- Windows Task Manager (Taskmgr)
- <SYSTEM32>\dwm.exe
- %WINDIR%\explorer.exe
- <SYSTEM32>\taskhost.exe
- iexplore.exe
- firefox.exe
- <Full path to file>
- from <Full path to file> to <Current directory>\old_<File name>.exe
- http://w.google.com/
- http://pa###bin.com/raw/AqndxJKK
- DNS ASK cx###0fWHA.com
- DNS ASK vV###gpbHF.com
- DNS ASK Dq###jjpVt.com
- DNS ASK O9###gYvBW.com
- DNS ASK Bn###q7FWX.com
- DNS ASK dj###qWmz4.com
- DNS ASK Dd###Jv2su.com
- DNS ASK w.google.com
- DNS ASK PT###qybAq.com
- DNS ASK pa###bin.com
- ClassName: 'Progman' WindowName: ''
- ClassName: 'Proxy Desktop' WindowName: ''
- ClassName: 'SystemTray_Main' WindowName: ''
- ClassName: 'Media Center Tray Applet' WindowName: ''
- ClassName: '' WindowName: 'View Available Networks'
- ClassName: 'BluetoothNotificationAreaIconWindowClass' WindowName: 'BluetoothNotificationAreaIconWindowClass'
- ClassName: 'BluetoothNotificationAreaIconWindowClass' WindowName: ''
- '%WINDIR%\explorer.exe'