Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\JQYgouDJ] 'Start' = '00000002'
- '%WINDIR%\Rakr1BJT.exe'
- '%PROGRAM_FILES%\smile.exe'
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\Rakr1BJT.bat
- %WINDIR%\Rakr1BJT.exe
- %WINDIR%\Rakr1BJT.bat
- %PROGRAM_FILES%\smile.mp3
- %PROGRAM_FILES%\smile.exe
- %WINDIR%\Rakr1BJT.exe
- %PROGRAM_FILES%\smile.exe
- 'wi####.f3322.org':886
- '<Private IP address>':886
- 'any':886
- DNS ASK wi####.f3322.org
- DNS ASK .#.
- ClassName: 'TAppBuilder' WindowName: '(null)'
- ClassName: 'MS_WINHELP' WindowName: '(null)'
- ClassName: 'WorkerW' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'