Technical Information
- [<HKLM>\System\CurrentControlSet\Services\ialdnwxf] 'ImagePath' = '<SYSTEM32>\supereceEnTY.sys'
- [<HKLM>\System\CurrentControlSet\Services\ialdnwxf] 'ImagePath' = '<SYSTEM32>\superec8h32P.sys'
- 'ialdnwxf' <SYSTEM32>\supereceEnTY.sys
- 'ialdnwxf' <SYSTEM32>\superec8h32P.sys
- %WINDIR%\syswow64\supereceenty.sys
- %WINDIR%\syswow64\superec8h32p.sys
- %ProgramFiles%\ie.exe
- %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012021061620210617\index.dat
- %WINDIR%\syswow64\supereceenty.sys
- %WINDIR%\syswow64\superec8h32p.sys
- %ProgramFiles%\ie.exe
- 'wm##.net':80
- 'p2##.com':80
- '52##xc.cn':80
- http://www.52##xc.cn/mx1.html
- http://www.p2##.com/2a.htm
- DNS ASK wm##.net
- DNS ASK tp.#61wg.cn
- DNS ASK p2##.com
- DNS ASK 52##xc.cn
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''