Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\security centre mana] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\security centre mana] 'ImagePath' = '%CommonProgramFiles%\System\ado\Library\scvchost.exe'
- <SYSTEM32>\svchost.exe
- %CommonProgramFiles%\System\ado\Library\scvchost.exe
- %TEMP%\egcdge.bat
- <SYSTEM32>\config\systemprofile\Local Settings\<INETFILES>\Content.IE5\6YQRA29M\checkip[1]
- <Full path to file>
- 'ch##kip.org':80
- http://www.ch##kip.org/ via ch##kip.org
- DNS ASK www.ch##kip.org
- '%CommonProgramFiles%\System\ado\Library\scvchost.exe'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\egcdge.bat