Technical Information
- [<HKLM>\System\CurrentControlSet\Services\RedGirl] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\RedGirl] 'ImagePath' = '<SYSTEM32>\RedGirl.exe -service'
- %WINDIR%\syswow64\redgirl.exe
- %WINDIR%\syswow64\tmp.bat
- %WINDIR%\syswow64\redgirl.dat
- ClassName: '' WindowName: 'Ö÷¶¯·ÀÓù ÐÅÏ¢'
- ClassName: '' WindowName: 'Ö÷¶¯·ÀÓù ¾¯±¨'
- ClassName: '' WindowName: 'Ö÷¶¯·ÀÓù ¾¯¸æ'
- ClassName: '' WindowName: 'Îļþ±£»¤ ¾¯¸æ'
- ClassName: '' WindowName: '¿¨°Í˹»ù»¥ÁªÍø°²È«Ì××° 6.0'
- ClassName: '' WindowName: '΢µãÖ÷¶¯·ÀÓùÈГВјГѕ '
- '%WINDIR%\syswow64\redgirl.exe' 1
- '%WINDIR%\syswow64\redgirl.exe' -service
- '%WINDIR%\syswow64\redgirl.exe' 1' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c <SYSTEM32>\tmp.bat' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c <SYSTEM32>\tmp.bat