Technical Information
- [HKLM\System\CurrentControlSet\Services\Ghijkl Nopqrstu Wxy] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Ghijkl Nopqrstu Wxy] 'ImagePath' = '<SYSTEM32>\svchost.exe -k imgsvc'
- 'Ghijkl Nopqrstu Wxy' <SYSTEM32>\svchost.exe -k imgsvc
- %ProgramFiles%\windows nt\accessories\fn34.exe
- C:\map508200.dll
- C:\heygirl.ddd
- C:\nettemp.ini
- %ProgramFiles(x86)%\lhij\kknd.psd
- C:\nettemp.ini
- C:\nettemp.ini
- from <Full path to file> to %WINDIR%\sync
- '14.##.107.10':80
- http://14.##.107.10/fn
- '%ProgramFiles%\windows nt\accessories\fn34.exe'
- '<SYSTEM32>\cmd.exe' /C "%ProgramFiles%\Windows NT\Accessories\fn34.exe"
- '<SYSTEM32>\cmd.exe' /C timeout /T 1 & move "<Full path to file>" "%WINDIR%\sync"
- '<SYSTEM32>\timeout.exe' /T 1