Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'softblow' = '"%PROGRAM_FILES%\softblow\softblow_m.exe"'
- [<HKLM>\SYSTEM\ControlSet001\Services\Network Security Service] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\softblow service] 'Start' = '00000002'
- '%PROGRAM_FILES%\softblow\softblow_d.exe'
- '%PROGRAM_FILES%\softblow\softblow_i.exe'
- %PROGRAM_FILES%\softblow\softblow_i.exe
- %PROGRAM_FILES%\softblow\softblow_d.exe
- %PROGRAM_FILES%\softblow\softblow_m.exe
- %PROGRAM_FILES%\softblow\softblow_u.exe
- %PROGRAM_FILES%\softblow\softblow_s.exe
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\$inst\2.tmp
- <SYSTEM32>\msvcr110.dll
- %WINDIR%\netsecurity.exe
- %WINDIR%\netclient.dll
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- 'www.se####click.co.kr':80
- www.se####click.co.kr/app/demonConfigUrl
- www.se####click.co.kr/app/appModule
- DNS ASK www.se####click.co.kr
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'