Technical Information
- [<HKLM>\System\CurrentControlSet\Services\SuperProServer] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\SuperProServer] 'ImagePath' = '%WINDIR%\Terms.EXE.exe'
- 'SuperProServer' %WINDIR%\Terms.EXE.exe
- %WINDIR%\terms.exe.exe
- 'fa###866go.top':81
- DNS ASK fa###866go.top
- DNS ASK r.###gyou.com
- '%WINDIR%\terms.exe.exe'