Technical Information
- [<HKLM>\System\CurrentControlSet\Services\NVIDIA Dissplay Drilverv] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\NVIDIA Dissplay Drilverv] 'ImagePath' = '%WINDIR%\guocyok88.exe'
- 'NVIDIA Dissplay Drilverv' %WINDIR%\guocyok88.exe
- %TEMP%\ixp000.tmp\server~1.exe
- %WINDIR%\guocyok88.exe
- %WINDIR%\guocyok88.exe
- %TEMP%\ixp000.tmp\server~1.exe
- 'ou###.3322.org':8000
- DNS ASK ou###.3322.org
- '%TEMP%\ixp000.tmp\server~1.exe'
- '%WINDIR%\guocyok88.exe'