Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '' = '%APPDATA%\iexplorer.exe'
- '<SYSTEM32>\rundll32.exe' InetCpl.cpl,ClearMyTracksByProcess 2
- '%APPDATA%\iexplorer.exe'
- '<SYSTEM32>\rundll32.exe' InetCpl.cpl,ClearMyTracksByProcess 8
- '<SYSTEM32>\rundll32.exe' InetCpl.cpl,ClearMyTracksByProcess 1
- %APPDATA%\iexplorer.exe
- %TEMP%\CRNJEUFU - 8-15-2016-3.30.18-PM.txt
- from <Full path to virus> to %TEMP%\tm187.tmp
- 'ft#.####oreign3.3owl.com':21
- 'wp#d':80
- 'sm##.163.com':25
- http://11#.#11.111.2/wpad.dat via wp#d
- DNS ASK ft#.####oreign3.3owl.com
- DNS ASK wp#d
- DNS ASK sm##.163.com
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''