Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\Internetset] 'Start' = '00000002'
- <SYSTEM32>\calc.exe
- ClassName: 'Filemonclass' WindowName: ''
- ClassName: 'Regmonclass' WindowName: ''
- C:\set.exe
- %PROGRAM_FILES%\sset.exe
- C:\AutoRun.inf
- %CommonProgramFiles%\Microsoft Shared\MSInfo\2010.txt
- %CommonProgramFiles%\Microsoft Shared\MSInfo\set.exe
- C:\set.exe
- %PROGRAM_FILES%\sset.exe
- %CommonProgramFiles%\Microsoft Shared\MSInfo\set.exe
- C:\AutoRun.inf
- %CommonProgramFiles%\Microsoft Shared\MSInfo\2010.txt
- 'yi#####2203.3322.org':8181
- DNS ASK yi#####2203.3322.org
- '<Private IP address>':1035
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'TSxmanage' WindowName: ''
- ClassName: '18467-41' WindowName: ''
- ClassName: '4823-00000029' WindowName: ''
- ClassName: 'TAppBuilder' WindowName: ''