Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\Neker] 'Start' = '00000002'
- '<SYSTEM32>\svchest.exe'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\9889.bat
- '<SYSTEM32>\svchost.exe' 23423
- %TEMP%\9889.bat
- <SYSTEM32>\svchest.exe
- %TEMP%\54089.tmp
- 'ha####s.3322.org':1900
- DNS ASK ha####s.3322.org