Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\Spooler] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\WinServerViewgx] 'Start' = '00000002'
- <SYSTEM32>\sys_temtraygx.exe
- <SYSTEM32>\cmd.exe /c c:\del.bat
- <SYSTEM32>\net1.exe start WinServerViewgx
- <SYSTEM32>\sc.exe create WinServerViewgx binpath= "<SYSTEM32>\sys_temtraygx.exe" type= share start= auto displayname= "systemtraygx" depend= RPCSS/Tcpip/IPSec
- <SYSTEM32>\spoolsv.exe
- C:\del.bat
- <SYSTEM32>\sys_temtraygxkaba.sub
- <SYSTEM32>\sys_temtraygx.txt
- <SYSTEM32>\sys_temtraygx.jpg
- <SYSTEM32>\hz_sys_temtraygx.dll
- <SYSTEM32>\sys_temtraygx.exe
- <SYSTEM32>\sys_temtraygx.ini
- <SYSTEM32>\hz_sys_temtraygx.dat
- <SYSTEM32>\keyHook.dll
- <SYSTEM32>\sys_temtraygx.exe
- <SYSTEM32>\sys_temtraygx.ini
- <SYSTEM32>\hz_sys_temtraygx.dat
- 'ba######9.host160.9free.net':80
- ba######9.host160.9free.net/ip.txt
- DNS ASK ba######9.host160.9free.net
- ClassName: 'MS_WINHELP' WindowName: ''