Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\RasConn] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\RpcSss] 'Start' = '00000002'
- '%TEMP%\MS08069.exe'
- '%TEMP%\MS08068.exe'
- '<SYSTEM32>\svchost.exe' -k netsvcs
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\shimgvw.dll,ImageView_Fullscreen %TEMP%\ry7sbmwV7O.jpg
- %TEMP%\MS08069.exe
- <SYSTEM32>\RpcSss.dll
- <SYSTEM32>\RasConn.dll
- %TEMP%\ry7sbmwV7O.jpg
- %TEMP%\r200898res46.wmv
- %TEMP%\MS08068.exe
- <SYSTEM32>\RpcSss.dll
- %TEMP%\MS08069.exe
- %TEMP%\MS08068.exe
- 'jp###.kmip.net':80
- 'jp###.kmip.net':809
- DNS ASK jp###.kmip.net
- ClassName: '' WindowName: ''
- ClassName: 'WMPlayerApp' WindowName: ''
- ClassName: 'Type32_Main_Window' WindowName: ''
- ClassName: '\MSITPro::EventQueue' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'ShImgVw:CPreviewWnd' WindowName: ''
- ClassName: 'WMP9DeskBand' WindowName: 'WMP9DeskBand'
- ClassName: 'ReBarWindow32' WindowName: ''