Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,%WINDIR%\wscntfy32.exe,%WINDIR%\help\svchost.exe'
- '%WINDIR%\mouse.exe'
- '%WINDIR%\wscntfy32.exe'
- '%WINDIR%\my_facebook_photo.exe'
- '%WINDIR%\unlock.exe' x lock.rar -o+ -p112233
- '<SYSTEM32>\wscript.exe' "%WINDIR%\run.vbs"
- %WINDIR%\mouse.exe
- %WINDIR%\wscntfy32.exe
- %WINDIR%\encoder.txt
- %WINDIR%\lock.rar
- %WINDIR%\my_facebook_photo.exe
- %WINDIR%\unlock.exe
- %WINDIR%\run.vbs
- 'r2####s.3322.org':80
- r2####s.3322.org/encoder.txt?37###
- DNS ASK r2####s.3322.org
- ClassName: 'Mozilla/4.0' WindowName: '%WINDIR%\mouse.exe'
- ClassName: 'Mozilla/4.0' WindowName: '%WINDIR%\wscntfy32.exe'
- ClassName: 'EDIT' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'