Technical Information
- [<HKLM>\System\CurrentControlSet\Services\Opqrst] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Opqrst] 'ImagePath' = '%WINDIR%\uyqwyc.exe'
- [<HKLM>\System\CurrentControlSet\Services\Defghi] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Defghi] 'ImagePath' = '%WINDIR%\fwjnwo.exe'
- C:\gta1.exe
- C:\gta2.exe
- %WINDIR%\uyqwyc.exe
- %WINDIR%\fwjnwo.exe
- C:\gta1.exe
- C:\gta2.exe
- from C:\gta1.exe to %WINDIR%\syswow64\1198156.bak
- from C:\gta2.exe to %WINDIR%\syswow64\1213937.bak
- 're#.#bfull.com':15950
- '10#.#0.247.228':8001
- '11#.#88.245.171':8001
- DNS ASK re#.#bfull.com
- 'C:\gta1.exe'
- 'C:\gta2.exe'
- '%WINDIR%\uyqwyc.exe'
- '%WINDIR%\fwjnwo.exe'
- '%WINDIR%\uyqwyc.exe' Win7
- '%WINDIR%\fwjnwo.exe' Win7
- 'C:\gta1.exe' ' (with hidden window)
- 'C:\gta2.exe' ' (with hidden window)