Technical Information
- [HKLM\System\CurrentControlSet\Services\3E51C8] 'ImagePath' = '%TEMP%\3E51C8.sys'
- [HKLM\SYSTEM\CurrentControlSet\Services\3E51C8] 'start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\81420] 'ImagePath' = '%TEMP%\81420.sys'
- [HKLM\System\CurrentControlSet\Services\zcb] 'ImagePath' = '%TEMP%\zcb.sys'
- '3E51C8' %TEMP%\3E51C8.sys
- '81420' %TEMP%\81420.sys
- 'zcb' %TEMP%\zcb.sys
- %WINDIR%\syswow64\myini.ini
- 'fh###.####cn-beijing.aliyuncs.com':443
- 'fh###.####cn-beijing.aliyuncs.com':443
- DNS ASK fh###.####cn-beijing.aliyuncs.com
- DNS ASK wt##che.com
- DNS ASK a.##cs.com
- DNS ASK b.##cs.com
- DNS ASK c.##cs.com
- DNS ASK 9z#.#5cs.com
- ClassName: '' WindowName: 'ВЎВЎВЎВЎВЎВЎ'