Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'conhost' = '%APPDATA%\Microsoft\conhost.exe'
- [<HKLM>\SYSTEM\ControlSet001\Control\Print\Providers\2387844480] 'Name' = '%TEMP%\2.tmp'
- [<HKLM>\SYSTEM\ControlSet001\Services\784b2a50] 'imagepath' = '%WINDIR%\TEMP\4.tmp'
- '%TEMP%\2f9c0711.exe' start%APPDATA%\dwm.exe%%APPDATA%
- '%TEMP%\2f9c0711.exe' start%TEMP%\csrss.exe%C:\DOCUME~1\%USERNAME%\LOCALS~1\Temp
- '%TEMP%\2f9c0711.exe'
- '%TEMP%\dc57f49c.exe'
- '%TEMP%\b5db2372.exe'
- <SYSTEM32>\spoolsv.exe
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1200' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1001' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '{A8A88C49-5EB2-4990-A1A2-0876022C854F}' = '{1a,37,61,59,23,52,35,0c,7a,5f,20,17,2f,1e,1a,19,0e,2b,01,73,13,37,13,12...
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1208' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '2000' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1405' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1209' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '{AEBA21FA-782A-4A90-978D-B72164C80120}' = '{1a,37,61,59,23,52,35,0c,7a,5f,20,17,2f,1e,1a,19,0e,2b,01,73,13,37,13,12...
- [<HKLM>\SYSTEM\ControlSet001\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings] 'ProxyEnable' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'ProxyServer' = 'http=127.0.0.1:60364'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'ProxyEnable' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] 'currentlevel' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1A10' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1400' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1601' = '00000000'
- %APPDATA%\Microsoft\conhost.exe
- %WINDIR%\Temp\4.tmp
- %APPDATA%\CA96.A04
- %TEMP%\1.tmp
- %TEMP%\dc57f49c.exe
- %TEMP%\b5db2372.exe
- %TEMP%\2f9c0711.exe
- %WINDIR%\Temp\4.tmp
- <DRIVERS>\etc\hosts
- %TEMP%\2.tmp
- from %TEMP%\b5db2372.exe to %TEMP%\3.tmp
- from %TEMP%\1.tmp to %TEMP%\2.tmp
- 'localhost':60364
- '74.##5.232.51':80
- 'gr###tar.com':80
- '67.##5.160.76':80
- http://www.google.com/ via localhost
- http://www.google.com/ via 74.##5.232.51
- http://gr###tar.com/avatar.php?gr################################################################################################################################################################...
- http://www.ya##o.com/ via 67.##5.160.76
- DNS ASK wo####otoblo.com
- DNS ASK www.google.com
- DNS ASK www.ya##o.com
- DNS ASK fr#####diaportal.com
- DNS ASK gr###tar.com
- DNS ASK fa####ogportal.com
- DNS ASK zo##dg.com