Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{0AA2D91F-FC72-DFB0-29A5-DCDE054FA77E}] 'stubpath' = ''
- '<SYSTEM32>\reg.exe' delete "HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{0AA2D91F-FC72-DFB0-29A5-DCDE054FA77E}" /f
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- <SYSTEM32>\V3Medic.exe
- <SYSTEM32>\PerfStringBackup.TMP
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- 'bl##.#ina.com.cn':80
- '17#.#39.190.38':80
- bl##.#ina.com.cn/s/blog_14557d58d0102vbkv.html
- 17#.#39.190.38/pro1.asp
- DNS ASK bl##.daum.net
- DNS ASK bl##.#ina.com.cn