Technical Information
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe,"<LS_APPDATA>\WIndowsSystemDLLHostService\svchost.exe"'
- '<LS_APPDATA>\WIndowsSystemDLLHostService\svchost.exe'
- <SYSTEM32>\taskhost.exe
- ecmd.exe
- <LS_APPDATA>\WIndowsSystemDLLHostService\svchost.exe
- DNS ASK dn#.##ftncsi.com
- DNS ASK pa######.chickenkiller.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: '' WindowName: '<Auxiliary name>'