Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'RPC Debugger Themes Performance System Host' = 'C:\asvkatvp\hensaiob.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Server Volume Accounts Gateway Parental] 'ImagePath' = 'C:\asvkatvp\hensaiob.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Server Volume Accounts Gateway Parental] 'Start' = '00000002'
- C:\asvkatvp\hensaiob.exe
- C:\asvkatvp\hfgjkui.exe
- C:\asvkatvp\pyclecaf
- %WINDIR%\asvkatvp\vvvnvznupgw
- C:\asvkatvp\vvvnvznupgw
- C:\asvkatvp\dxw3be6dztgfotv.exe
- C:\asvkatvp\hfgjkui.exe
- C:\asvkatvp\hensaiob.exe
- C:\asvkatvp\dxw3be6dztgfotv.exe
- %WINDIR%\asvkatvp\vvvnvznupgw
- %WINDIR%\asvkatvp\vvvnvznupgw
- '87.##.38.225':33631
- '70.##2.38.96':41500
- '86.#8.69.58':22437
- '77.##8.205.139':22969
- '20#.#7.225.58':33073
- '81.##7.50.99':52074
- '18#.#38.249.34':37331
- '73.##.228.84':36884
- '18#.#22.43.28':46084
- '12#.#60.112.138':27440
- 'C:\asvkatvp\hfgjkui.exe' "c:\asvkatvp\hensaiob.exe"
- 'C:\asvkatvp\hensaiob.exe'
- 'C:\asvkatvp\dxw3be6dztgfotv.exe'