Technical Information
- [HKLM\System\CurrentControlSet\Services\zhdslulxi] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\zhdslulxi] 'ImagePath' = '<SYSTEM32>\products.exe zhdslulxi'
- 'zhdslulxi' <SYSTEM32>\products.exe zhdslulxi
- %WINDIR%\syswow64\products.exe
- from <Full path to file> to %WINDIR%\syswow64\wostmp\_817422886_2135572538
- '1.###.248.27':27930
- '<LOCALNET>.56.16':27930
- '<LOCALNET>.56.17':27930
- '<LOCALNET>.56.18':27930
- '36.##.33.170':27930
- '<LOCALNET>.56.19':27930
- '36.##.195.104':27930
- '<LOCALNET>.56.15':27930
- '<LOCALNET>.56.20':27930
- '37.##6.93.255':27930
- '<LOCALNET>.56.23':27930
- '<LOCALNET>.56.24':27930
- '<LOCALNET>.56.25':27930
- '<LOCALNET>.56.26':27930
- '<LOCALNET>.56.21':27930
- '<LOCALNET>.56.22':27930
- '<LOCALNET>.56.14':27930
- '<LOCALNET>.56.13':27930
- '<LOCALNET>.56.12':27930
- '<LOCALNET>.56.1':27930
- '2.##7.39.2':27930
- '<LOCALNET>.56.2':27930
- '<LOCALNET>.56.3':27930
- '<LOCALNET>.56.4':27930
- '<LOCALNET>.56.5':27930
- '<LOCALNET>.56.0':27930
- '27.##.245.64':27930
- '<LOCALNET>.56.7':27930
- '<LOCALNET>.56.8':27930
- '<LOCALNET>.56.9':27930
- '36.##.37.188':27930
- '<LOCALNET>.56.10':27930
- '<LOCALNET>.56.11':27930
- '<LOCALNET>.56.6':27930
- '41.##.186.196':27930
- '<LOCALNET>.56.27':27930
- '%WINDIR%\syswow64\products.exe' zhdslulxi