Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'sfwfrlji' = '<SYSTEM32>\xrkuvhji.exe'
- '<SYSTEM32>\xrkuvhji.exe'
- <SYSTEM32>\Info.ini
- <SYSTEM32>\xrkuvhji.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\nei_00[1].jpg
- <SYSTEM32>\xrkuvhji.hlp
- 'www.lu###30812.com':80
- www.lu###30812.com/xe/images/nei_00.jpg
- DNS ASK www.lu###30812.com
- ClassName: '49B46336-BA4D-4905-9824-D282F05F6576' WindowName: '(null)'