Technical Information
- [HKLM\System\CurrentControlSet\Services\ialdnwxf] 'ImagePath' = '<Current directory>\superec.ProcessMemory.sys'
- 'ialdnwxf' <Current directory>\\superec.ProcessMemory.sys
- 'ialdnwxf' <Current directory>\superec.ProcessMemory.sys
- <Current directory>\superec.processmemory.sys
- %WINDIR%\temp\udd9b06.tmp
- %LOCALAPPDATA%\microsoft\internet explorer\msimgsiz.dat
- %WINDIR%\temp\udd9b06.tmp
- 'dn###086.com':80
- 'mm##3.top':443
- 'hm.##idu.com':443
- http://www.dn###086.com/
- http://www.dn###086.com/tj.js
- http://www.dn###086.com/common.js
- 'mm##3.top':443
- 'hm.##idu.com':443
- DNS ASK 77##g.com
- DNS ASK dn###086.com
- DNS ASK mm##3.top
- DNS ASK hm.##idu.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''