Technical Information
- %HOMEPATH%\Start Menu\Programs\Startup\vdocd.lnk
- '<SYSTEM32>\rundll32.exe' %TEMP%\dcodv.dat,OKL06
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE'
- '%ProgramFiles%\Windows Media Player\wmplayer.exe' Media Player\wmplayer.exe
- '<SYSTEM32>\rundll32.exe' %TEMP%\dcodv.dat,OKL04
- '<SYSTEM32>\rundll32.exe' %TEMP%\dcodv.dat,OKL00
- '<SYSTEM32>\rundll32.exe' %TEMP%\dcodv.dat,OKL01
- '<SYSTEM32>\rundll32.exe' %TEMP%\dcodv.dat,OKL03
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '2500' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] '2500' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '2500' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '2500' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '2500' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '1609' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] '1609' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '1609' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1609' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1609' = '00000000'
- %TEMP%\vdocd.pad
- %TEMP%\vdocd.js
- %TEMP%\dcodv.dat
- %ALLUSERSPROFILE%\Application Data\dcodv.dat
- 'wh###illber.com':80
- '37.##9.53.199':80
- '37.##9.53.199':443
- '37.##9.53.169':443
- DNS ASK wh###illber.com
- ClassName: 'WMP9DeskBand' WindowName: 'WMP9DeskBand'
- ClassName: 'ReBarWindow32' WindowName: ''
- ClassName: 'Type32_Main_Window' WindowName: ''
- ClassName: '\MSITPro::EventQueue' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''