Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\DisplayName] 'Start' = '00000002'
- '<SYSTEM32>\SDFGGUBO.EXE' /install /silent
- '<SYSTEM32>\net1.exe' start DisplayName
- '<SYSTEM32>\regsvr32.exe' /s "<SYSTEM32>\NHJLUN.DLL"
- <SYSTEM32>\LSDINXJUAVHSKI.DLL
- <SYSTEM32>\wbem\WUCTZHNVBME.DLL
- <SYSTEM32>\SDFGGUBO.EXE
- <SYSTEM32>\BRQBHE.DLL
- <DRIVERS>\TXKGSHAGJFUNT.DAT
- <SYSTEM32>\8u1mk8w7.dll
- <SYSTEM32>\NHJLUN.DLL
- <SYSTEM32>\SQMNSAGFKP.INI
- 'ad.##kead.com':80
- '67.##5.160.76':80
- ad.##kead.com/start.asp?id##
- 67.##5.160.76/
- DNS ASK ad.##kead.com
- DNS ASK cn.##hoo.com
- ClassName: 'MS_WINHELP' WindowName: ''