Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] 'odbcx86' = '{A2AB2390-CA89-11CF-9C87-00CB806327AD}'
- [<HKLM>\SYSTEM\ControlSet001\Services\usbmini] 'Start' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\wbem\_smss.exe' = '<SYSTEM32>\wbem\_smss.exe:*:Enabled:smss'
- '<SYSTEM32>\wbem\_smss.exe'
- NtQuerySystemInformation, handler: usbmini.sys
- NtQueryDirectoryFile, handler: usbmini.sys
- <SYSTEM32>\wbem\_smss.exe
- <DRIVERS>\usbmini.sys
- %TEMP%\IEEEEEE001
- <SYSTEM32>\wbem\_smss.exe
- <SYSTEM32>\odbcx86.dll
- 'ff##.co.uk':80
- 'localhost':1039
- ff##.co.uk/notify.php?id#####################################################
- DNS ASK google.com
- DNS ASK ff##.co.uk