Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\WindowService] 'ImagePath' = '"%TEMP%\WindowService.exe"'
- [<HKLM>\SYSTEM\ControlSet001\Services\WindowService] 'Start' = '00000002'
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1220
- '%TEMP%\WindowService.exe'
- %TEMP%\WindowService.Lib.dll
- %TEMP%\zlib.net.dll
- %TEMP%\WindowService.exe
- %TEMP%\System.Data.SQLite.xml
- %TEMP%\System.Data.SQLite.Linq.dll
- %TEMP%\dw.log
- %TEMP%\26140.dmp
- %TEMP%\WindowService.InstallState
- %TEMP%\InstallUtil.InstallLog
- %TEMP%\WindowService.InstallLog
- %TEMP%\System.Data.SQLite.dll
- %TEMP%\ati_upd.dll
- %TEMP%\config.json
- %TEMP%\128x128.png
- %TEMP%\x64\SQLite.Interop.dll
- %TEMP%\x86\SQLite.Interop.dll
- %TEMP%\NLog.dll
- %TEMP%\NLog.xml
- %TEMP%\NLog.config
- %TEMP%\Newtonsoft.Json.dll
- %TEMP%\Newtonsoft.Json.xml
- 'fr###eoip.net':80
- 'ds##decs.pw':443
- 'wp#d':80
- http://fr###eoip.net/json/
- http://11#.#11.111.1/wpad.dat via wp#d
- DNS ASK fr###eoip.net
- DNS ASK ds##decs.pw
- DNS ASK wp#d
- ClassName: 'Shell_TrayWnd' WindowName: ''