Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] 'AppInit_DLLs' = ' '
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows] 'LoadAppInit_DLLs' = '00000001'
- [<HKLM>\System\CurrentControlSet\Services\0f6d5a24] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\0f6d5a24] 'ImagePath' = '"<SYSTEM32>\rundll32.exe" "%ProgramFiles(x86)%\LighterModulator\LighterModulator.dll",serv'
- %TEMP%\tf467126b8.dll
- %ProgramFiles(x86)%\lightermodulator\lightermodulator.dll
- %TEMP%\tf467126b8.dll
- 'bb#.com':80
- DNS ASK bb#.com
- DNS ASK te###ne.info
- DNS ASK te##ine.net
- DNS ASK fa###rygood.net
- '%WINDIR%\syswow64\rundll32.exe' "%ProgramFiles(x86)%\LighterModulator\LighterModulator.dll",serv -install
- '<SYSTEM32>\rundll32.exe' "%ProgramFiles(x86)%\LighterModulator\LighterModulator.dll",serv