Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Processus hote pour les services Windows' = '%APPDATA%\sys32\svchost.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Processus hote pour les services Windows' = '\sys32\svchost.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 's55X81fP' = '%HOMEPATH%\u68Z87vH\svchost.exe'
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe'
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
- C:\sys32\svchost.exe
- %APPDATA%\imlgs\27-02-2014
- %APPDATA%\install.imp
- %APPDATA%\sys32\svchost.exe
- %HOMEPATH%\m52U68yX.UI7
- %TEMP%\aut1.tmp
- %HOMEPATH%\o91D10kD.txt
- C:\<Virus name>.exe
- %HOMEPATH%\o91D10kD.txt
- %HOMEPATH%\m52U68yX.UI7
- %TEMP%\aut1.tmp
- 'ki######urgy22.no-ip.biz':4547
- DNS ASK ki######urgy22.no-ip.biz
- ClassName: 'Indicator' WindowName: '(null)'