Technical Information
- [HKLM\System\CurrentControlSet\Services\KIS_BZ] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\KIS_BZ] 'ImagePath' = '<Full path to file>'
- 'KIS_BZ' <Full path to file>
- %WINDIR%\syswow64\diskinfo.dll
- %WINDIR%\syswow64\kdlock.dll
- %WINDIR%\syswow64\kisverifycontent.dll
- %WINDIR%\syswow64\mdlock.dll
- %WINDIR%\syswow64\config\systemprofile\appdata\roaming\microsoft\windows\ietldcache\index.dat
- %WINDIR%\syswow64\config\systemprofile\appdata\roaming\microsoft\windows\cookies\system@fkw[1].txt
- %WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\62axopq5\login_h[1].jsp
- %WINDIR%\syswow64\kdlock.dll
- 'fa##co.cn':80
- 'i.##w.com':80
- http://i.##w.com/ajax/login_h.jsp?cm####################
- http://www.fa##co.cn/ajax/login_h.jsp?cm####################
- DNS ASK fa##co.cn
- DNS ASK i.##w.com
- '%WINDIR%\syswow64\net.exe' start MySQL5_OA
- '%WINDIR%\syswow64\net1.exe' start MySQL5_OA
- '%WINDIR%\syswow64\net.exe' start MySQL5_OA' (with hidden window)