Technical Information
- [HKLM\System\CurrentControlSet\Services\svchostl] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\svchostl] 'ImagePath' = '%ProgramFiles(x86)%\Windows Photo Gallery\zh-CN\xx'
- 'svchostl' %ProgramFiles(x86)%\Windows Photo Gallery\zh-CN\xx
- %TEMP%\ixp000.tmp\aa3.exe
- %TEMP%\ixp001.tmp\aw4.exe
- %ProgramFiles(x86)%\windows photo gallery\zh-cn\xx
- %WINDIR%\uninstal.bat
- %ProgramFiles(x86)%\windows photo gallery\zh-cn\xx
- %TEMP%\ixp001.tmp\aw4.exe
- %TEMP%\ixp000.tmp\aa3.exe
- DNS ASK ha####o.8800.org
- '%TEMP%\ixp000.tmp\aa3.exe'
- '%TEMP%\ixp001.tmp\aw4.exe'
- '%ProgramFiles(x86)%\windows photo gallery\zh-cn\xx'
- '%WINDIR%\syswow64\cmd.exe' /c %WINDIR%\uninstal.bat
- '%TEMP%\ixp000.tmp\aa3.exe' ' (with hidden window)
- '%TEMP%\ixp001.tmp\aw4.exe' ' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c %WINDIR%\uninstal.bat' (with hidden window)