Technical Information
- [<HKLM>\System\CurrentControlSet\Services\UxSms] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Themes] 'Start' = '00000002'
- C:\softxlic.ini
- from <Full path to file> to <Current directory>\6j9vv6.exe
- 'xc##fdc.com':80
- http://www.xc##fdc.com/kss_io/io.php?v=###########################################
- DNS ASK xc##fdc.com
- ClassName: '' WindowName: 'ExecPubg.exe'
- ClassName: '' WindowName: 'TslGame.exe'
- ClassName: '' WindowName: 'TslGame_BE.exe'
- ClassName: '' WindowName: 'TslGame_EAC.exe'
- ClassName: '' WindowName: 'TslGame_UC.exe'
- ClassName: '' WindowName: 'ucsvc.exe'
- ClassName: '' WindowName: 'BEService_x64.exe'
- '%WINDIR%\syswow64\powercfg.exe' /h off