Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\SSFK] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\SSFK] 'ImagePath' = '%ProgramFiles%\SFK\SSFK.exe -s'
- [<HKLM>\SYSTEM\ControlSet001\Services\WdMan] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\WdMan] 'ImagePath' = '%ALLUSERSPROFILE%\Application Data\LwinpL\WFini.exe -svr'
- '%APPDATA%\setup1\TSvr.exe'
- '%APPDATA%\setup1\TSvr.exe' -ptid=eve0822 -si -is
- '%ProgramFiles%\SFK\SSFK.exe' -s
- '<Current directory>\_SSpm\Everything.exe' /ptid=eve0822 /S
- '<Current directory>\_SSpm\ihpul.exe' -ptid=eve0822 -si
- '<Current directory>\_SSpm\wpm.exe' -ptid=eve0822 -is
- '<Current directory>\_SSpm\QQBrowser.exe' -ptid=eve0822
- '%ALLUSERSPROFILE%\Application Data\LwinpL\WFini.exe' -svr
- '%ALLUSERSPROFILE%\Application Data\LwinpL\WFini.exe' -run
- %ALLUSERSPROFILE%\Application Data\LwinpL\tmpx\{2029B70D-A131-414B-942A-D6BF6A7FAC91}.html
- <SYSTEM32>\tmp6.html
- <Current directory>\EN_207500.html
- <Current directory>\EN_206750.html
- <Current directory>\EN_184484.html
- <Current directory>\EN_183687.html
- <Current directory>\tmp8.html
- %ALLUSERSPROFILE%\Application Data\LwinpL\WFini.exe
- %TEMP%\nsg2.tmp\System.dll
- <Current directory>\EN_248156.html
- <Current directory>\EN_247500.html
- %ProgramFiles%\SFK\SSFK.exe
- %ProgramFiles%\SFK\SFK.ini
- %APPDATA%\setup1\TSvr.exe
- %TEMP%\nsg2.tmp\exdll.dll
- %APPDATA%\setup1\msvcr120.dll
- %APPDATA%\setup1\msvcp120.dll
- %TEMP%\HomePage.dat
- <Current directory>\_SSpm\ihpul.exe
- <Current directory>\_SSpm\Everything.exe
- <Current directory>\_SSpm\QQBrowser.exe
- <Current directory>\_SSpm\qks.exe
- <Current directory>\_SSpm\cf.ini
- <Current directory>\_SSpm\39.json
- <Current directory>\_SSpm\EOF.exe
- <Current directory>\_SSpm\DataBase
- <Current directory>\_SSpm\QQBrowserFrame.dll
- <Current directory>\EN_153515.html
- <Current directory>\en_150343.html
- <Current directory>\Z
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\z[1].php
- <Current directory>\_SSpm\UnEverything.exe
- <Current directory>\_SSpm\saber.exe
- <Current directory>\_SSpm\wpm.exe
- <Current directory>\_SSpm\winzipper.exe
- <SYSTEM32>\tmp6.html
- %TEMP%\nsg2.tmp\exdll.dll
- %TEMP%\nsg2.tmp\System.dll
- <Current directory>\_SSpm\cf.ini
- <Current directory>\Z
- <Current directory>\tmp8.html
- 'www.nu###arch.com':80
- 'd1#######qrqmu.cloudfront.net':80
- 'localhost':1040
- 'localhost':1037
- 'd4#######i6x7.cloudfront.net':80
- http://d4#######i6x7.cloudfront.net/v4/gtg/XXwareXXirtualXIDEXHardXDrive_11000000000000000001?ac#######################
- http://d1#######qrqmu.cloudfront.net/windowspm/up?pt####################################################################################################################
- http://d4#######i6x7.cloudfront.net/v4/gtg/XXwareXXirtualXIDEXHardXDrive_11000000000000000001?ac###############################################
- http://d4#######i6x7.cloudfront.net/v4/gtg/XXwareXXirtualXIDEXHardXDrive_11000000000000000001?ac####################################################
- http://d4#######i6x7.cloudfront.net/v4/gtg/XXwareXXirtualXIDEXHardXDrive_11000000000000000001?ac############################
- http://d4#######i6x7.cloudfront.net/v4/gtg/XXwareXXirtualXIDEXHardXDrive_11000000000000000001?ac#########################
- http://www.nu###arch.com/search/z.php
- http://d4#######i6x7.cloudfront.net/v4/gtg/XXwareXXirtualXIDEXHardXDrive_11000000000000000001?ac###########################
- http://d4#######i6x7.cloudfront.net/v4/gtg/XXwareXXirtualXIDEXHardXDrive_11000000000000000001?ac#####################################
- http://d4#######i6x7.cloudfront.net/v4/gtg/XXwareXXirtualXIDEXHardXDrive_11000000000000000001?ac######################
- http://d4#######i6x7.cloudfront.net/v4/gtg/XXwareXXirtualXIDEXHardXDrive_11000000000000000001?ac#####################
- http://d4#######i6x7.cloudfront.net/v4/gtg/XXwareXXirtualXIDEXHardXDrive_11000000000000000001?ac#############################
- DNS ASK lo#.#ery911.com
- DNS ASK d1#######qrqmu.cloudfront.net
- DNS ASK d4#######i6x7.cloudfront.net
- DNS ASK www.nu###arch.com