Technical Information
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'HKLM' = '%TEMP%\InstallDir\Server.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'HKCU' = '%TEMP%\InstallDir\Server.exe'
- [<HKLM>\Software\Wow6432Node\Microsoft\Active Setup\Installed Components\{8251KKI0-580G-8M1S-0C3X-OU6I3535W01X}] 'StubPath' = '%TEMP%\InstallDir\Server.exe restart'
- %WINDIR%\syswow64\svchost.exe
- %APPDATA%\microsoft\windows\7o2uc.cfg
- %TEMP%\installdir\server.exe
- %APPDATA%\microsoft\windows\7o2uc.dat
- %APPDATA%\microsoft\windows\7o2uc.cfg
- %TEMP%\installdir\server.exe
- %APPDATA%\microsoft\windows\7o2uc.dat
- DNS ASK ab####sm1.zapto.org
- '%WINDIR%\syswow64\svchost.exe'