Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\Wstbra rtpszdno] 'Start' = '00000002'
- '%PROGRAM_FILES%\Microsoft Uwquss\Gfphfjg.exe'
- '%WINDIR%\addinss1.exe'
- '%PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE' http://www.km##823.com
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\kmy0823[1]
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\NetSyst61[1].jpg
- %WINDIR%\AppPatch\NetSyst61.dll
- %APPDATA%\E_UIEngine\90afea1eeb37be7a93471c36152ab43a\90afea1eeb37be7a93471c36152ab43a.jpg
- %WINDIR%\addinss1.exe
- %PROGRAM_FILES%\Microsoft Uwquss\Gfphfjg.exe
- 'localhost':1034
- 'dh####.gg.txxsf.com':80
- 'localhost':1030
- 'www.km##823.com':80
- dh####.gg.txxsf.com/ads/NetSyst61.jpg
- www.km##823.com/
- DNS ASK dh####.gg.txxsf.com
- DNS ASK www.km##823.com
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: '' WindowName: '(null)'