Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '' = '%WINDIR%\svchoat.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Wsnmlk xpbuuzem] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\Wsnmlk xpbuuzem] 'ImagePath' = '%WINDIR%\Oxnbakx.exe'
- %TEMP%\AFX1.tmp
- %TEMP%\AFX2.tmp
- %TEMP%\AFX3.tmp
- %TEMP%\AFX4.tmp
- %WINDIR%\Oxnbakx.exe
- %TEMP%\AFX5.tmp
- %TEMP%\AFX6.tmp
- %TEMP%\AFX7.tmp
- %TEMP%\AFX8.tmp
- %WINDIR%\Temp\AFX9.tmp
- %WINDIR%\Temp\AFXA.tmp
- %WINDIR%\Temp\AFXB.tmp
- %WINDIR%\Temp\AFXC.tmp
- 'localhost':2014
- '%WINDIR%\Oxnbakx.exe'