Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ctfmon32.exe' = '%ALLUSERSPROFILE%\Application Data\rundll32.exe %ALLUSERSPROFILE%\Application Data\ferito.dat,XFG00'
- %HOMEPATH%\Start Menu\Programs\Startup\regmonstd.lnk
- '%ALLUSERSPROFILE%\Application Data\rundll32.exe' Data\rundll32.exe %ALLUSERSPROFILE%\Application Data\ferito.dat,XFG06
- '%ALLUSERSPROFILE%\Application Data\rundll32.exe' Data\rundll32.exe %ALLUSERSPROFILE%\Application Data\ferito.dat,XFG04
- '%ProgramFiles%\Windows Media Player\wmplayer.exe' Media Player\wmplayer.exe
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE'
- '%ALLUSERSPROFILE%\Application Data\rundll32.exe' Data\rundll32.exe %ALLUSERSPROFILE%\Application Data\ferito.dat,XFG01
- '%ALLUSERSPROFILE%\Application Data\rundll32.exe' Data\rundll32.exe %ALLUSERSPROFILE%\Application Data\ferito.dat,XFG00
- '%ALLUSERSPROFILE%\Application Data\rundll32.exe' Data\rundll32.exe %ALLUSERSPROFILE%\Application Data\ferito.dat,XFG03
- '%ALLUSERSPROFILE%\Application Data\rundll32.exe' Data\rundll32.exe %ALLUSERSPROFILE%\Application Data\ferito.dat,XFG02
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '2500' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] '2500' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '2500' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '2500' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '2500' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '1609' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] '1609' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '1609' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1609' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1609' = '00000000'
- %ALLUSERSPROFILE%\Application Data\otiref.js
- %TEMP%\tratra.lnk
- %ALLUSERSPROFILE%\Application Data\sdaksda.txt
- %ALLUSERSPROFILE%\Application Data\rundll32.exe
- %ALLUSERSPROFILE%\Application Data\ferito.dat
- %ALLUSERSPROFILE%\Application Data\otiref.pad
- '37.##9.53.199':80
- '37.##9.53.169':80
- 'wh###illber.com':443
- '37.##9.53.169':443
- '37.##9.53.199':443
- DNS ASK wh###illber.com
- ClassName: 'WMP9DeskBand' WindowName: 'WMP9DeskBand'
- ClassName: 'ReBarWindow32' WindowName: ''
- ClassName: 'Type32_Main_Window' WindowName: ''
- ClassName: '\MSITPro::EventQueue' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''