Technical Information
- [<HKLM>\System\CurrentControlSet\Services\ALSysIO] 'ImagePath' = '%TEMP%\ALSysIO64.sys'
- 'ALSysIO' %TEMP%\ALSysIO64.sys
- %TEMP%\7zipsfx.000\coretemp.ini
- %TEMP%\7zipsfx.000\languages\zh-cn.lng
- %TEMP%\7zipsfx.000\coretemp.exe
- %TEMP%\alsysio64.sys
- %TEMP%\alsysio64.sys
- 'al##u.com':80
- DNS ASK al##u.com
- '%TEMP%\7zipsfx.000\coretemp.exe'