Technical Information
- [HKLM\System\CurrentControlSet\Services\fastuserswitchingcompatibility] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\fastuserswitchingcompatibility] 'ImagePath' = '<SYSTEM32>\svchost.exe -k netsvcs'
- 'fastuserswitchingcompatibility' <SYSTEM32>\svchost.exe -k netsvcs
- C:\eorooxbjxt
- <Current directory>\ucmdobvetg
- %TEMP%\yrrkcvnemx.dat
- <Current directory>\ucmdobvetg
- from %TEMP%\yrrkcvnemx.dat to %ALLUSERSPROFILE%\application data\storm\update\%sessionname%\tqjgf.cc3
- DNS ASK co##.f.360.cn
- DNS ASK bi###.8800.org
- 'C:\eorooxbjxt' a -s<Full path to file>