Technical Information
- [HKLM\System\CurrentControlSet\Services\holbwhjj] 'ImagePath' = '<PATH_SAMPLE>.sys'
- [HKLM\System\CurrentControlSet\Services\holbwhjj] 'Start' = '00000000'
- [HKLM\System\CurrentControlSet\Services\holbwhjj] 'Start' = '00000001'
- 'holbwhjj' <PATH_SAMPLE>.sys
- '10#.#01.172.229':80
- 'ba##u.com':80
- 't.##.com':80
- '22#.#9.68.50':80
- 'bl##.csdn.net':80
- 'ab#.#plxy.com':8080
- '1.##4.187.4':80
- '58.##3.140.96':80
- '61.##3.70.228':80
- http://www.ba##u.com/p/°ІИ«ВМЙ«ПВФШ°Й/detail
- DNS ASK ba##u.com
- DNS ASK my.##years.com
- DNS ASK 52.##05210.com
- DNS ASK t.##.com
- DNS ASK bl##.tianya.cn
- DNS ASK bl##.csdn.net
- DNS ASK ab#.#plxy.com
- DNS ASK 12#.#78lv.com