Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'WindowsUpdate' = '%APPDATA%\udk\irs.exe %APPDATA%\udk\irp-wpo'
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe' -f "%TEMP%\VRcCrArB.txt"
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe' -f "%TEMP%\rcwLzJI.txt"
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe' -f "%TEMP%\uJcNifarR.txt"
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe' -f "%TEMP%\SnnHJb.txt"
- '%APPDATA%\udk\irs.exe' %APPDATA%\udk\CGIUN
- '%APPDATA%\udk\irs.exe' irp-wpo
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe' -f "%TEMP%\bISDDEoVS.txt"
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe'
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe
- [<HKLM>\SOFTWARE\Nero\Installation\Families\Nero 8\Info]
- [<HKLM>\SOFTWARE\O&O\O&O Defrag\8.0\Pro\licenses]
- [<HKLM>\SOFTWARE\PowerQuest\PartitionMagic\8.0\UserInfo]
- [<HKLM>\SOFTWARE\Macromedia\Fireworks\7\Registration]
- [<HKLM>\SOFTWARE\Macromedia\Flash\7\Registration]
- [<HKLM>\SOFTWARE\Ahead\Installation\Families\Nero 7\Info]
- [<HKLM>\SOFTWARE\TechSmith\Camtasia Studio\4.0]
- [<HKLM>\SOFTWARE\TuneUp\Utilities\6.0]
- [<HKLM>\SOFTWARE\TuneUp\Utilities\8.0]
- [<HKLM>\SOFTWARE\Nullsoft\Winamp]
- [<HKCU>\Software\TechSmith\SnagIt\8]
- [<HKLM>\SOFTWARE\TechSmith\SnagIt\8]
- [<HKCU>\Software\RIT\The Bat!]
- [<HKLM>\SOFTWARE\Macromedia\Dreamweaver\7\Registration]
- [<HKCU>\Software\Google\Google Talk\Accounts]
- [<HKCU>\Software\America Online\aim6\Passwords]
- [<HKCU>\Software\Paltalk]
- [<HKCU>\Software\Microsoft\Office\Outlook\OMI Account Manager\Accounts]
- [<HKCU>\Software\Microsoft\Internet Account Manager\Accounts]
- [<HKCU>\Software\Microsoft\Windows Live Mail]
- [<HKCU>\Software\IMVU\username]
- [<HKLM>\SOFTWARE\CyberLink\PowerProducer\3.0\UserReg]
- [<HKLM>\SOFTWARE\Elcom\Advanced PDF Password Recovery\Registration]
- [<HKLM>\SOFTWARE\Elcom\Advanced ZIP Password Recovery\Registration]
- [<HKCU>\Software\IMVU\password]
- [<HKCU>\Software\Yahoo\pager]
- [<HKLM>\SOFTWARE\Adobe\Photoshop\7.0\Registration]
- %APPDATA%\udk\aci.mp3
- %APPDATA%\udk\CGIUN
- %TEMP%\YvTUJL4.bmp
- %APPDATA%\udk\xev.ico
- %APPDATA%\udk\usp.icm
- %APPDATA%\udk\jhm.dat
- %TEMP%\SnnHJb.txt
- %TEMP%\sx_win_bin.tmp
- %TEMP%\uJcNifarR.txt
- %TEMP%\bISDDEoVS.txt
- %TEMP%\rcwLzJI.txt
- %TEMP%\VRcCrArB.txt
- %APPDATA%\udk\kum.docx
- %APPDATA%\udk\cdn.bmp
- %APPDATA%\udk\hdc.dat
- %APPDATA%\udk\uah.mp3
- %APPDATA%\udk\aes.docx
- %APPDATA%\udk\irp-wpo
- %APPDATA%\udk\irs.exe
- %APPDATA%\udk\wql.xl
- %APPDATA%\udk\scw.pdf
- %APPDATA%\udk\tmb.icm
- %APPDATA%\udk\eja.docx
- %APPDATA%\udk\iwu.mp4
- %APPDATA%\udk\ena.ppt
- %APPDATA%\udk\irs.exe
- %TEMP%\SnnHJb.txt
- %TEMP%\sx_win_bin.tmp
- %TEMP%\uJcNifarR.txt
- %TEMP%\VRcCrArB.txt
- %APPDATA%\udk\CGIUN
- %TEMP%\bISDDEoVS.txt
- %TEMP%\rcwLzJI.txt
- 'co####xsoftware.com':80
- 'wp#d':80
- http://co####xsoftware.com/geoip/geoip.php
- http://11#.#11.111.1/wpad.dat via wp#d
- DNS ASK co####xsoftware.com
- DNS ASK wp#d
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''