Technical Information
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'XXX_C32B0CAD' = '"<SYSTEM32>\cmd.exe" /c "%WINDIR%\GGTALL\GGTupdate.exe" /R'
- %WINDIR%\syswow64\svchost.exe
- %WINDIR%\ggtall\ggtupdate.exe
- %TEMP%\temp0.bat
- %WINDIR%\ggtall\ggtupdate.kinf
- 'localhost':135
- DNS ASK ip#.##t.gg-team.net
- DNS ASK gg####2014.vicp.cc
- DNS ASK fu####1003.oicp.net
- '%WINDIR%\syswow64\svchost.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\Temp0.bat" "
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\Temp0.bat" "' (with hidden window)