Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\Rspdates Apxplicatioanjrq] 'Start' = '00000002'
- <SYSTEM32>\svchost.exe -k netsvcs
- %TEMP%\Xy132750nd.temp
- <SYSTEM32>\45210.dll
- %TEMP%\TEAM25.reg
- %TEMP%\MyInformations.ini
- %TEMP%\fengshao0.txt
- <SYSTEM32>\45210.dll
- %TEMP%\MyInformations.ini
- %TEMP%\TEAM25.reg
- %TEMP%\fengshao0.txt
- 'mi###6.3322.org':1001
- DNS ASK mi###6.3322.org
- '<Private IP address>':1035