Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'kszzul_kys' = '%ALLUSERSPROFILE%\Microsoft\Network\netsvcs.exe'
- '%ProgramFiles%\internet explorer\iexplore.exe' http://down.81830.info:802/ad2.htm?3___http://go.microsoft.com/fwlink/?LinkId=69157
- %TEMP%\aut4346.tmp
- %ALLUSERSPROFILE%\kcr.cate
- %TEMP%\aut4346.tmp
- DNS ASK do##.81830.info
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%ProgramFiles%\internet explorer\iexplore.exe' http://down.81830.info:802/ad2.htm?3___http://go.microsoft.com/fwlink/?LinkId=69157' (with hidden window)