Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Update Services' = '%WINDIR%\temp.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windows Update Services' = '%WINDIR%\temp.exe'
- %WINDIR%\Explorer.EXE
- %WINDIR%\temp.exe
- %WINDIR%\temp.exe
- 'xo####nfla9a.com':80
- xo####nfla9a.com/login/temp/load.php?si#############################
- DNS ASK xo####nfla9a.com
- ClassName: 'SysListView32' WindowName: '(null)'
- ClassName: 'Indicator' WindowName: '(null)'
- ClassName: '#32770' WindowName: '(null)'
- ClassName: 'RegEdit_RegEdit' WindowName: '(null)'