Technical Information
- [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] 'Ô¶³Ì¹ÜÀГ' = '%WINDIR%\helpen.exe'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'GrpConv' = 'grpconv -o'
- %WINDIR%\syswow64\svchost.exe
- %TEMP%\xiaoyu.exe
- %TEMP%\wmxd.ini
- %WINDIR%\wmxd.ini
- %WINDIR%\helpen.exe
- %TEMP%\ô¶³ì¹üà Г.inf
- %TEMP%\xytp.bat
- %WINDIR%\syswow64\wmxd.ini
- nul
- %TEMP%\ô¶³ì¹üà Г.inf
- %LOCALAPPDATA%\microsoft\windows\explorer\explorerstartuplog_runonce.etl
- %TEMP%\ô¶³ì¹üà Г.inf
- DNS ASK a4####0636.3322.org
- '%TEMP%\xiaoyu.exe'
- '%WINDIR%\helpen.exe'
- '%WINDIR%\syswow64\rundll32.exe' setupapi,InstallHinfSection DefaultInstall 128 %TEMP%\\Ô¶³Ì¹ÜÀГ.inf
- '%WINDIR%\syswow64\runonce.exe' -r
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\xytp.bat
- '%WINDIR%\syswow64\svchost.exe'
- '%WINDIR%\syswow64\grpconv.exe' -o
- '%WINDIR%\syswow64\ping.exe' -n 6 127.0.0.1
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\xytp.bat' (with hidden window)