Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\A017wiZMo] 'Start' = '00000001'
- <SYSTEM32>\A017wiZMo.sys
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\ddhh[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\mf.92fz[1]
- <SYSTEM32>\MakeAtManage.sys
- <SYSTEM32>\3122iscHX.sys
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\mine[1]
- <SYSTEM32>\3122iscHX.systmp
- <SYSTEM32>\3122iscHX.sys
- from <SYSTEM32>\3122iscHX.systmp to <SYSTEM32>\3122iscHX.sys
- '99#######fz.stor.sinaapp.com':80
- 'mf.#2fz.com':80
- 't.##.com':80
- 'localhost':1039
- mf.#2fz.com/
- 99#######fz.stor.sinaapp.com/O/ddhh.txt
- t.##.com/sddosas/mine
- DNS ASK bu########uding.stor.sinaapp.com
- DNS ASK zh###.#0.upaiyun.com
- DNS ASK my.##years.com
- DNS ASK t.##.com
- DNS ASK 99#######fz.stor.sinaapp.com
- DNS ASK mf.#2fz.com
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'