Technical Information
- [HKLM\System\CurrentControlSet\Services\oldold] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\oldold] 'ImagePath' = '"%WINDIR%\SysWOW64\oldold.exe"'
- 'oldold' "%WINDIR%\SysWOW64\oldold.exe"
- 'oldold' %WINDIR%\SysWOW64\oldold.exe
- from <Full path to file> to %WINDIR%\syswow64\oldold.exe
- '14#.#17.246.57':80
- '24.##1.176.48':443