Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<Full path to virus>' = '<Full path to virus>:*:Enabled:Microsoft Update'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\_uninsep.bat" "
- outpost.exe
- ntvdm.exe
- ZONEALARM.EXE
- zapro.exe
- NAVAPW32.EXE
- Drwebupw.exe
- AVSYNMGR.EXE
- GUARD.EXE
- fsav.exe
- <SYSTEM32>\base64zip.sys
- <SYSTEM32>\base64exe.sys
- %WINDIR%\bloodred.zip
- %TEMP%\_uninsep.bat
- <SYSTEM32>\bloodred.exe
- 'www.ka##a.com':80
- www.ka##a.com/
- DNS ASK www.ka##a.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'