Technical Information
- [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] 'svchost' = '%WINDIR%\svchost.exe /e:vbs <SYSTEM32>\SVCHosT.DAT'
- [HKLM\SYSTEM\ControlSet001\Services\TlntSvr] 'Start' = '00000002'
- <Drive name for removable media>:\bupt.dat
- hidden files
- '%WINDIR%\svchost.exe' /E:vbS <SYSTEM32>\SVCHosT.DAT
- [HKCU\Software\Microsoft\Internet Account Manager]
- [HKLM\Software\Microsoft\Windows Mail]
- [HKCU\Software\Microsoft\Windows Mail]
- <SYSTEM32>\svchost.dat
- %WINDIR%\svchost.exe
- <SYSTEM32>\liam.dat
- <SYSTEM32>\svchost.dat
- %WINDIR%\svchost.exe
- <SYSTEM32>\liam.dat
- <Drive name for removable media>:\bupt.dat
- DNS ASK ip##8.cn
- DNS ASK sm##.qq.com