Technical Information
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'AMD Graphic' = '%LOCALAPPDATA%\AMD Drivers\AMDgraphics.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'AMD Graphic' = '%LOCALAPPDATA%\AMD Drivers\AMDgraphics.exe'
- [<HKLM>\System\CurrentControlSet\Services\IKEEXT] 'Start' = '00000002'
- %LOCALAPPDATA%\amd drivers\amdgraphics.exe
- unc\xxlrtdoyjao\users\winadmin-setup.exe
- http://ip###odb.com/ip_query.php
- http://www.wh###smyip.com/automation/n09230945.asp
- DNS ASK wh###smyip.com
- DNS ASK ip###odb.com
- DNS ASK 2h###4us.net
- '%LOCALAPPDATA%\amd drivers\amdgraphics.exe'
- '%WINDIR%\syswow64\netsh.exe' Advfirewall set Currentprofile State off