Technical Information
- [<HKLM>\System\CurrentControlSet\Services\DOoLQ] 'Start' = '00000001'
- [<HKLM>\System\CurrentControlSet\Services\DOoLQ] 'ImagePath' = '<DRIVERS>\DOoLQ.sys'
- 'DOoLQ' <DRIVERS>\DOoLQ.sys
- <DRIVERS>\doolq.sys
- %WINDIR%\temp\uddb579.tmp
- <DRIVERS>\etc\hosts
- %WINDIR%\temp\uddb579.tmp
- '<DNS_SERVER>':80
- 'fh##q.com':80
- http://www.fh##q.com/top.html
- DNS ASK a.##dlq.com
- DNS ASK b.##dlq.com
- DNS ASK c.##dlq.com
- DNS ASK pT#.#hdlq.com
- DNS ASK h.###yjy.com
- DNS ASK fh##q.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c rd "<DRIVERS>\etcAB1MQ" /S /Q' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c rd "<DRIVERS>\etcAB1MQ" /S /Q