Technical Information
- [<HKLM>\System\CurrentControlSet\Services\Cdefgh Jklmnopq Stu] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Cdefgh Jklmnopq Stu] 'ImagePath' = '<SYSTEM32>\BRemotes.exe'
- C:\4160.vbs
- C:\4160.vbs
- from <Full path to file> to %WINDIR%\syswow64\bremotes.exe
- '<LOCALNET>.7.27':81
- http://us##.#zone.qq.com/
- DNS ASK ww#####48908.f3322.org
- DNS ASK us##.#zone.qq.com
- '%WINDIR%\syswow64\wscript.exe' "C:\4160.vbs"
- '%WINDIR%\syswow64\wscript.exe' "C:\4160.vbs"' (with hidden window)