Technical Information
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'QV593pK2' = '%ALLUSERSPROFILE%\scandep\{bYyF4tRAzTXGWfjBp7Al}\QV593pK2.exe'
- %ALLUSERSPROFILE%\scandep\{byyf4traztxgwfjbp7al}\qv593pk2.exe
- %ALLUSERSPROFILE%\scandep\{byyf4traztxgwfjbp7al}\httpsapi.dll
- %ALLUSERSPROFILE%\scandep\{byyf4traztxgwfjbp7al}\log.dll
- %ALLUSERSPROFILE%\scandep\{byyf4traztxgwfjbp7al}\qv593pk2.txt
- %LOCALAPPDATA%\178bfbff00050657
- %ALLUSERSPROFILE%\scandep\{byyf4traztxgwfjbp7al}\key
- 'xd##.selfip.com':8080
- 'xd##.selfip.com':12345
- http://xd##.##lfip.com:8080/9x.dll via xd##.selfip.com
- 'xd##.selfip.com':12345
- DNS ASK xd##.selfip.com
- ClassName: '' WindowName: ''
- '%ALLUSERSPROFILE%\scandep\{byyf4traztxgwfjbp7al}\qv593pk2.exe'
- '<Full path to file>' 490A300A560A5A0A780A650A6D0A780A6B0A670A4E0A6B0A7E0A6B0A560A790A690A6B0A640A6E0A6F0A7A0A560A710A680A530A730A4C0A3E0A7E0A580A4B0A700A5E0A520A4D0A5D0A6C0A600A480A7A0A3D0A4B0A660A770A560A5B0A5C0A3...' (with hidden window)
- '%ALLUSERSPROFILE%\scandep\{byyf4traztxgwfjbp7al}\qv593pk2.exe' ' (with hidden window)