Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\Windows Audio Driver] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\Windows Audio Driver] 'ImagePath' = 'cmd.exe /c start %CommonProgramFiles%\Services\svchost.exe'
- <SYSTEM32>\cmd.exe
- %CommonProgramFiles%\Services\system\svchost.exe
- %CommonProgramFiles%\Services\svchost.exe
- %ProgramFiles%\Windows NT\DESKT0P.INI
- C:\Documents and Settings\LocalService\Local Settings\<INETFILES>\Content.IE5\CJCTQ25G\kj[1].jpg
- 'kj.###ilingyuan.com':80
- http://kj.###ilingyuan.com/kj.jpg
- DNS ASK kj.###ilingyuan.com
- '%CommonProgramFiles%\Services\svchost.exe'
- '<SYSTEM32>\cmd.exe' /c start %CommonProgramFiles%\Services\svchost.exe