Technical Information
- [<HKLM>\System\CurrentControlSet\Services\ialdnwxf] 'ImagePath' = '<SYSTEM32>\superecj5xVa.sys'
- [<HKLM>\System\CurrentControlSet\Services\ialdnwxf] 'ImagePath' = '<SYSTEM32>\superecaifon.sys'
- %WINDIR%\syswow64\superecj5xva.sys
- %WINDIR%\syswow64\superecaifon.sys
- %ProgramFiles%\ie.exe
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\syswow64\superecj5xva.sys
- %WINDIR%\syswow64\superecaifon.sys
- %ProgramFiles%\ie.exe
- http://www.wm##.net/soft/ie.exe
- http://www.cf###gfu.com/sj.txt
- http://www.cf###gfu.com/
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- DNS ASK wm##.net
- DNS ASK tp.#61wg.cn
- DNS ASK cf###gfu.com
- DNS ASK microsoft.com
- ClassName: '' WindowName: 'Microsoft Internet Explorer'
- ClassName: 'DDEMLMom' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''