Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Loader' = '%APPDATA%\syssl.exe -lds'
- '%APPDATA%\syssl.exe' -lds
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram %APPDATA%\syssl.exe "Windows Update Viewer" ENABLE
- %TEMP%\d132046
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\doit[1].php
- %APPDATA%\syssl.exe
- %TEMP%\d132046
- 'gy###eplace.cn':80
- gy###eplace.cn/ld/doit.php?v=#############
- DNS ASK gy###eplace.cn
- ClassName: 'Indicator' WindowName: '(null)'