Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\Opqrst] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\Opqrst] 'ImagePath' = '%WINDIR%\svchost.exe'
- %WINDIR%\explorerrr.exe
- %WINDIR%\Server.exe
- %WINDIR%\svchost.exe
- from <Full path to file> to %TEMP%\125609\...\TemporaryFile
- from %WINDIR%\explorerrr.exe to %TEMP%\129593\...\TemporaryFile
- from %WINDIR%\Server.exe to <SYSTEM32>\132265.bak
- 'xu#.##login2.qq.com':443
- 'lo######t.ptlogin2.qq.com':4300
- 'w1.##exi.tech':44421
- '20##.ip138.com':80
- http://20##.ip138.com/ic.asp
- DNS ASK xu#.##login2.qq.com
- DNS ASK lo######t.ptlogin2.qq.com
- DNS ASK w1.##exi.tech
- DNS ASK 20##.ip138.com
- ClassName: 'vguiPopupWindow' WindowName: 'Steam ????'
- ClassName: 'vguiPopupWindow' WindowName: 'Steam µЗВј'
- ClassName: 'vguiPopupWindow' WindowName: 'Steam'
- '%WINDIR%\explorerrr.exe'
- '%WINDIR%\Server.exe'
- '%WINDIR%\svchost.exe'