Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QPNotify.exe] 'debugger' = 'debugfile.exe'
- %WINDIR%\syswow64\svchost.exe
- %TEMP%\aut5bdf.tmp
- <SYSTEM32>\zjdcetcm.dll
- %WINDIR%\syswow64\wodskd\pid.txt
- %TEMP%\autf93a.tmp
- %WINDIR%\syswow64\vcdcttvgzh.dll
- %WINDIR%\bjnxla.txt
- %TEMP%\aut2d1c.tmp
- %WINDIR%\syswow64\bchvyk\cgecqc.dll
- %TEMP%\aut2d2d.tmp
- %WINDIR%\syswow64\bchvyk\set.ini
- <LS_APPDATA>\microsoft\windows\<INETFILES>\low\content.ie5\b66z8ors\desktop.ini
- %WINDIR%\syswow64\kfydwb\cfg.ini
- %WINDIR%\syswow64\kfydwb\aozjsc.dll
- %TEMP%\aut3712.tmp
- %WINDIR%\syswow64\kfydwb\ymxrota.dll
- %TEMP%\aut3732.tmp
- %WINDIR%\syswow64\kfydwb\config.ini
- %TEMP%\aut3743.tmp
- %WINDIR%\syswow64\zxeelhyscy.dat
- %TEMP%\aut46b5.tmp
- %WINDIR%\syswow64\tnuctqdznsb.dll
- %TEMP%\kwfeooi
- %TEMP%\autee2d.tmp
- %TEMP%\autee1c.tmp
- %WINDIR%\syswow64\wodskd\onxbmz.exe
- %TEMP%\autecd5.tmp
- %TEMP%\aut60e0.tmp
- %TEMP%\oqhdjvo
- <LS_APPDATA>\microsoft\windows\<INETFILES>\low\desktop.ini
- <LS_APPDATA>\microsoft\windows\<INETFILES>\low\content.ie5\desktop.ini
- <LS_APPDATA>\microsoft\windows\history\low\desktop.ini
- <LS_APPDATA>\microsoft\windows\history\low\history.ie5\desktop.ini
- <LS_APPDATA>\microsoft\windows\<INETFILES>\low\content.ie5\index.dat
- <LS_APPDATA>\microsoft\windows\<INETFILES>\low\content.ie5\9r2i41uv\desktop.ini
- <LS_APPDATA>\microsoft\windows\<INETFILES>\low\content.ie5\e76o5z9a\desktop.ini
- %WINDIR%\mac.txt
- %TEMP%\aut3701.tmp
- <LS_APPDATA>\microsoft\windows\<INETFILES>\low\content.ie5\q1dec032\desktop.ini
- <LS_APPDATA>\microsoft\windows\history\low\history.ie5\index.dat
- %TEMP%\aut7004.tmp
- %WINDIR%\syswow64\ocghfawz.dll
- <Current directory>\ibqfks.exe
- %TEMP%\autce8e.tmp
- %WINDIR%\gumomvi\hnujqx.exe
- %TEMP%\autd574.tmp
- %TEMP%\vwgkmxj
- %WINDIR%\icriwe.txt
- %TEMP%\gfyxjtq
- %APPDATA%\microsoft\windows\cookies\low\index.dat
- %WINDIR%\waw5wsut\waw5wsut.dll
- <LS_APPDATA>\microsoft\windows\<INETFILES>\low\desktop.ini
- <LS_APPDATA>\microsoft\windows\<INETFILES>\low\content.ie5\desktop.ini
- <LS_APPDATA>\microsoft\windows\<INETFILES>\low\content.ie5\9r2i41uv\desktop.ini
- <LS_APPDATA>\microsoft\windows\<INETFILES>\low\content.ie5\e76o5z9a\desktop.ini
- <LS_APPDATA>\microsoft\windows\<INETFILES>\low\content.ie5\q1dec032\desktop.ini
- <LS_APPDATA>\microsoft\windows\<INETFILES>\low\content.ie5\b66z8ors\desktop.ini
- <LS_APPDATA>\microsoft\windows\history\low\history.ie5\desktop.ini
- <LS_APPDATA>\microsoft\windows\history\low\desktop.ini
- %TEMP%\aut5bdf.tmp
- %TEMP%\aut46b5.tmp
- %TEMP%\aut3743.tmp
- %TEMP%\aut3732.tmp
- %TEMP%\aut3712.tmp
- %TEMP%\aut3701.tmp
- %WINDIR%\syswow64\bchvyk\set.ini
- %TEMP%\aut2d2d.tmp
- %TEMP%\aut2d1c.tmp
- %WINDIR%\bjnxla.txt
- %WINDIR%\syswow64\wodskd\onxbmz.exe
- %TEMP%\autf93a.tmp
- %WINDIR%\syswow64\wodskd\pid.txt
- <SYSTEM32>\zjdcetcm.dll
- %TEMP%\autee2d.tmp
- %TEMP%\kwfeooi
- %TEMP%\autee1c.tmp
- %TEMP%\autecd5.tmp
- %WINDIR%\icriwe.txt
- %TEMP%\vwgkmxj
- %TEMP%\autd574.tmp
- %TEMP%\autce8e.tmp
- %TEMP%\aut7004.tmp
- %TEMP%\oqhdjvo
- %TEMP%\aut60e0.tmp
- %TEMP%\gfyxjtq
- %WINDIR%\mac.txt
- %WINDIR%\waw5wsut\waw5wsut.dll
- from <Full path to file> to <Current directory>\gevsrs.exe
- 'ap#.#illp.cn':80
- 'li##.58guyu.com':80
- 'do####.58guyu.com':9559
- http://se#.#dwjp.net/up/ytkj.xml
- http://www.w5##.info/up/tj/ytkj.htm
- http://js.##ers.51.la/15007433.js
- http://ia.#1.la/go1?id###########################################################################################################################################################################...
- http://p1.##wjp.com/ytkj/d/k9.rar
- http://39.#8.83.68/set/d7e8.txt
- http://ip.##ai310.com/
- http://47.##0.20.142/index.php/inface/Heart/getConfigDyn?m_##############################################
- http://47.##.214.214/server/client/server.txt?58############
- DNS ASK w5##.info
- DNS ASK se#.#dwjp.net
- DNS ASK js.##ers.51.la
- DNS ASK s4.#nzz.com
- DNS ASK ia.#1.la
- DNS ASK p1.##wjp.com
- DNS ASK ip.##ai310.com
- DNS ASK ap#.#illp.cn
- DNS ASK tc#.#illp.cn
- DNS ASK li##.58guyu.com
- DNS ASK do####.58guyu.com
- '<LOCALNET>.51.255':51052
- '255.255.255.255':3779
- '255.255.255.255':3881
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- ClassName: 'Progman' WindowName: 'Program Manager'
- '<Current directory>\ibqfks.exe' /ErrorStdOut
- '%WINDIR%\gumomvi\hnujqx.exe'
- '%WINDIR%\syswow64\wodskd\onxbmz.exe' /errorstdout
- '%WINDIR%\syswow64\cmd.exe' /c netstat -ano >>%WINDIR%\icriwe.txt' (with hidden window)
- '%WINDIR%\syswow64\svchost.exe' ' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ping 127.0.0.1 -n 3&del /q "%WINDIR%\SysWOW64\wodskd\onxbmz.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c netstat -ano >>%WINDIR%\bjnxla.txt' (with hidden window)
- '%WINDIR%\syswow64\rundll32.exe' "%WINDIR%\syswow64\WININET.dll",DispatchAPICall 1
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\FirewallControlPanel.dll,ShowNotificationDialog /configure /ETOnly 0 /OnProfiles 6 /OtherAllowed 0 /OtherBlocked 0 /OtherEdgeAllowed 0 /NewBlocked 2 "<Current directory>\gevsrs.exe"
- '%WINDIR%\syswow64\cmd.exe' /c netstat -ano >>%WINDIR%\icriwe.txt
- '%WINDIR%\syswow64\netstat.exe' -ano
- '%WINDIR%\syswow64\svchost.exe'
- '<SYSTEM32>\cmd.exe' /c ping 127.0.0.1 -n 3&del /q "%WINDIR%\SysWOW64\wodskd\onxbmz.exe"
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 3
- '%WINDIR%\syswow64\cmd.exe' /c netstat -ano >>%WINDIR%\bjnxla.txt
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\FirewallControlPanel.dll,ShowNotificationDialog /configure /ETOnly 0 /OnProfiles 6 /OtherAllowed 0 /OtherBlocked 0 /OtherEdgeAllowed 0 /NewBlocked 4 "%WINDIR%\syswow64\svchost.exe"