Technical Information
- [<HKLM>\System\CurrentControlSet\Services\rrdwfjkwqt32] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\rrdwfjkwqt32] 'ImagePath' = '%ProgramFiles%\010\rrdwfjkwqt32.exe run options=00100010100000000000000000000000 source=EC2A950B-0688-468A-9F2C-45B813760A...
- 'rrdwfjkwqt32' %ProgramFiles%\010\rrdwfjkwqt32.exe run options=00100010100000000000000000000000 source=EC2A950B-0688-468A-9F2C-45B813760A51
- %TEMP%\nsub00d.tmp\system.dll
- %ProgramFiles%\010\rrdwfjkwqt32.exe
- %TEMP%\nsub00d.tmp\nsexec.dll
- %ProgramFiles%\ec2a950b-0688-468a-9f2c-45b813760a51\uninstaller.exe
- %TEMP%\nsub00d.tmp\nsexec.dll
- %TEMP%\nsub00d.tmp\system.dll
- DNS ASK dq#######bd2n.cloudfront.net
- '%ProgramFiles%\010\rrdwfjkwqt32.exe' install source="EC2A950B-0688-468A-9F2C-45B813760A51" options="00100010100000000000000000000000"
- '%ProgramFiles%\010\rrdwfjkwqt32.exe' run options=00100010100000000000000000000000 source=EC2A950B-0688-468A-9F2C-45B813760A51
- '%ProgramFiles%\010\rrdwfjkwqt32.exe' install source="EC2A950B-0688-468A-9F2C-45B813760A51" options="00100010100000000000000000000000"' (with hidden window)