Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'OWDrdbvHvdWmk' = '%ALLUSERSPROFILE%\OWDrdbvHvdWmk.exe'
- Windows Task Manager (Taskmgr)
- [HKCU\Software\Microsoft\Internet Explorer\Download] 'CheckExeSignatures' = 'no'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments] 'SaveZoneInformation' = '00000001'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Associations] 'LowRiskFileTypes' = '/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq...
- %ALLUSERSPROFILE%\owdrdbvhvdwmk.exe
- from <Full path to file> to %TEMP%\tmpea8d.tmp
- 'fi###hin.org':80
- DNS ASK se###happle.org
- DNS ASK se####belief.org
- DNS ASK cl###calm.org
- DNS ASK fi###hin.org
- DNS ASK se###hways.org
- DNS ASK fi####vertisem.org
- DNS ASK se####modern.org
- '%ALLUSERSPROFILE%\owdrdbvhvdwmk.exe'