Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\TCPZ] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\WajgSvc] 'Start' = '00000002'
- <SYSTEM32>\ipconfig.exe /flushdns
- <SYSTEM32>\ping.exe -n 5 127.0.0.1
- <SYSTEM32>\svchost.exe -k WajgSvc
- <SYSTEM32>\rundll32.exe wajgaprnlib.dll,ServiceInstall
- <SYSTEM32>\sc.exe config WajgSvc start= AUTO
- %WINDIR%\DelCache.bat
- <DRIVERS>\tcpz-x86d.sys
- <SYSTEM32>\wajgaprnlib.dll
- <SYSTEM32>\wajgaprnlib.dll
- 'in.##jaca.com':21
- 'so##.jajaca.com':80
- so##.jajaca.com/lib.zip
- DNS ASK in.##jaca.com
- DNS ASK so##.jajaca.com
- '<Private IP address>':1035