Technical Information
- [HKLM\System\CurrentControlSet\Services\PfService] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\PfService] 'ImagePath' = '%ProgramFiles(x86)%\kuqi\PfServer.exe'
- 'PfService' %ProgramFiles(x86)%\kuqi\PfServer.exe
- %TEMP%\is-nhfb1.tmp\<File name>.tmp
- %TEMP%\is-17i5i.tmp\_isetup\_regdll.tmp
- %TEMP%\is-17i5i.tmp\_isetup\_setup64.tmp
- %TEMP%\is-17i5i.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-17i5i.tmp\urlnetget.dll
- %ProgramFiles(x86)%\kuqi\is-tlq5g.tmp
- %ProgramFiles(x86)%\kuqi\ad.ini
- %TEMP%\is-17i5i.tmp\urlnetget.dll
- %TEMP%\is-17i5i.tmp\_isetup\_regdll.tmp
- %TEMP%\is-17i5i.tmp\_isetup\_setup64.tmp
- %TEMP%\is-17i5i.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-nhfb1.tmp\<File name>.tmp
- from %ProgramFiles(x86)%\kuqi\is-tlq5g.tmp to %ProgramFiles(x86)%\kuqi\pfserver.exe
- DNS ASK ma##.##rvice.cnnuo.com
- DNS ASK c1.####ice.cnnuo.com
- '%TEMP%\is-nhfb1.tmp\<File name>.tmp' /SL5="$20258,898620,53248,<Full path to file>"
- '%ProgramFiles(x86)%\kuqi\pfserver.exe' /install /SILENT
- '%ProgramFiles(x86)%\kuqi\pfserver.exe'