Technical Information
- [HKLM\System\CurrentControlSet\Services\CreateSvcRpc_1259489] 'ImagePath' = 'cmd /c C:\Users\Public\KK.exe'
- 'CreateSvcRpc_1259489' cmd /c C:\Users\Public\KK.exe
- 'NAME01' C:\Zdd174cxy.sys
- C:\users\public\pro.exe
- C:\users\public\kk.exe
- %WINDIR%\temp\e_n60005\krnln.fnr
- %WINDIR%\temp\e_n60005\spec.fne
- %WINDIR%\temp\e_n60005\mp3.run
- C:\zdd174cxy.sys
- '10#.#06.189.92':80
- http://10#.#06.189.92/a206.233.129.110.txt
- http://10#.#06.189.92/s206.233.129.110.txt
- http://10#.#06.189.92/KK.TXT
- 'C:\users\public\pro.exe'
- 'C:\users\public\kk.exe'
- '%WINDIR%\syswow64\cmd.exe' /c tasklist | findstr /i 360tray.exe
- '%WINDIR%\syswow64\tasklist.exe'
- '%WINDIR%\syswow64\findstr.exe' /i 360tray.exe
- '<SYSTEM32>\cmd.exe' /c C:\Users\Public\KK.exe