Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] '543254y' = '%HOMEPATH%\543254y\66601.vbs'
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
- %HOMEPATH%\543254y\cKmxzY.LTS
- %HOMEPATH%\543254y\RYKarZWXZsJ.exe
- %HOMEPATH%\543254y\LqkdxoT.SSX
- %HOMEPATH%\543254y\LwJIDIwQEahS.LVR
- %HOMEPATH%\543254y\25886.cmd
- %HOMEPATH%\543254y\66601.vbs
- %HOMEPATH%\543254y\cKmxzY.LTS
- %HOMEPATH%\543254y\RYKarZWXZsJ.exe
- %HOMEPATH%\543254y\LqkdxoT.SSX
- %HOMEPATH%\543254y\LwJIDIwQEahS.LVR
- %HOMEPATH%\543254y\66601.vbs
- %HOMEPATH%\543254y\25886.cmd
- 'an###king.net':3333
- DNS ASK an###king.net
- ClassName: 'EDIT' WindowName: ''
- '%HOMEPATH%\543254y\RYKarZWXZsJ.exe' LqkdxoT.SSX
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe'