Technical Information
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\notepad.exe] 'Debugger' = 'systeem.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Thunder.exe] 'Debugger' = 'systeem.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qq.exe] 'Debugger' = 'systeem.exe'
- %WINDIR%\syswow64\seriver.exe
- %WINDIR%\syswow64\systeem.exe
- %WINDIR%\syswow64\seriver.exe
- %WINDIR%\syswow64\systeem.exe
- DNS ASK aa#.#anxire.com
- '%WINDIR%\syswow64\systeem.exe'
- '%WINDIR%\syswow64\seriver.exe'
- '%WINDIR%\syswow64\systeem.exe' ' (with hidden window)
- '%WINDIR%\syswow64\seriver.exe' ' (with hidden window)