Technical Information
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'sysconf32' = '%WINDIR%\sysconf32.vbs'
- %WINDIR%\sysconf32.vbs
- 'so#m.cz':80
- 'so#m.cz':443
- 'x1.#.lencr.org':80
- http://www.so#m.cz/projects/webdoor/enter.php?cl###############
- http://x1.#.lencr.org/
- 'so#m.cz':443
- DNS ASK so#m.cz
- DNS ASK x1.#.lencr.org
- ClassName: 'Static' WindowName: ''
- '<SYSTEM32>\wscript.exe' "%WINDIR%\sysconf32.vbs"
- '%ProgramFiles%\internet explorer\iexplore.exe' -Embedding
- '<SYSTEM32>\wscript.exe' "%WINDIR%\sysconf32.vbs"' (with hidden window)