Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\Chain] 'Start' = '00000002'
- '<SYSTEM32>\svchost.exe' -k netsvcs
- %WINDIR%\FuckYou.reg
- %TEMP%\203359_res.tmp
- %TEMP%\DogKiller.sys
- %WINDIR%\FuckYou.txt
- <SYSTEM32>\AntiRk.dll
- %WINDIR%\FuckYou.reg
- %WINDIR%\FuckYou.txt
- %TEMP%\DogKiller.sys
- from %TEMP%\203359_res.tmp to <SYSTEM32>\AntiRk.dll