Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\ialdnwxf] 'ImagePath' = '<Current directory>\my.sys'
- '<Current directory>\1000.exe'
- NtQuerySystemInformation, handler: unknown
- NtReadFile, handler: unknown
- NtQueryDirectoryFile, handler: unknown
- NtOpenSection, handler: unknown
- NtOpenThread, handler: unknown
- NtTerminateProcess, handler: unknown
- NtWriteFile, handler: unknown
- NtSetValueKey, handler: unknown
- NtSetSecurityObject, handler: unknown
- NtSetSystemInformation, handler: unknown
- NtCreateSection, handler: unknown
- NtDeleteKey, handler: unknown
- NtCreateKey, handler: unknown
- NtClose, handler: unknown
- NtCreateFile, handler: unknown
- NtOpenKey, handler: unknown
- NtOpenProcess, handler: unknown
- NtOpenFile, handler: unknown
- NtDeleteValueKey, handler: unknown
- NtLoadDriver, handler: unknown
- <Current directory>\1000.exe
- <Current directory>\my.sys
- <Current directory>\1000.exe
- <Current directory>\test.ini
- <Current directory>\my.sys
- 'sw##.#####n-shenzhen.aliyuncs.com':80
- http://sw##.#####n-shenzhen.aliyuncs.com/up.txt
- DNS ASK sw##.#####n-shenzhen.aliyuncs.com
- ClassName: 'Shell_TrayWnd' WindowName: ''