Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'MseUpdate' = 'rundll32.exe <SYSTEM32>\midimapbits.dll,About'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'MseUpdate' = 'rundll32.exe <SYSTEM32>\midimapbits.dll,About'
- [<HKLM>\SYSTEM\ControlSet001\Services\BITS] 'Start' = '00000002'
- '<SYSTEM32>\svchost.exe' -k netsvcs
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\midimapbits.dll,About
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\view[1].php
- C:\a.dat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\view[1].php
- <SYSTEM32>\midimapbits.dll
- %TEMP%\version361.dat
- %WINDIR%\Temp\version361.dat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\view[1].php
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\view[1].php
- 'www.la###l.co.kr':80
- www.la###l.co.kr/file/ab/view.php?m=########################################
- DNS ASK www.la###l.co.kr
- ClassName: 'Indicator' WindowName: '(null)'