Technical Information
- [HKLM\System\CurrentControlSet\Services\slehqwzdwtw] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\slehqwzdwtw] 'ImagePath' = '<SYSTEM32>\svchost.exe -k netsvcs'
- [HKLM\SYSTEM\CurrentControlSet\Services\slehqwzdwtw\Parameters] 'ServiceDll' = '%ProgramFiles(x86)%\slehqwzdwtw\slehqwzdwtw.dll'
- 'slehqwzdwtw' <SYSTEM32>\svchost.exe -k netsvcs
- %TEMP%\nsc537d.tmp
- %TEMP%\nsh539d.tmp\system.dll
- %TEMP%\nsh539d.tmp\math.dll
- %TEMP%\nsh539d.tmp\nscmds2.dll
- %ProgramFiles(x86)%\slehqwzdwtw\slehqwzdwtw.dll
- %TEMP%\nsh539d.tmp\nscmds3.dll
- 'gr##pby.kr':80
- http://www.gr##pby.kr/check_counter.php?pi##########################################
- DNS ASK wi###wnum.com
- DNS ASK gr##pby.kr