Technical Information
- [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Syslemnrwvl.exe'
- %TEMP%\lpath.ini
- %TEMP%\2l.dat
- %TEMP%\3l.dat
- %TEMP%\4l.dat
- %TEMP%\syslamwindwsa.exe
- %TEMP%\syslemnrwvl.exe
- %TEMP%\2l.dat
- %TEMP%\3l.dat
- %TEMP%\4l.dat
- %TEMP%\syslamwindwsa.exe
- %TEMP%\syslemnrwvl.exe
- %TEMP%\lpath.ini
- <Full path to file>
- 'aq.#q.com':80
- 'aq.#q.com':443
- '19#.#32.210.172':80
- 'oc##.#igicert.cn':80
- http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?95##############
- http://oc##.#igicert.cn/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRdfbJlK8FvT8EKTy%2FQWk9HlJQmegQUKyMWgRtHiYqQeuzoMtRsjnL5ziUCEAg5io5wOn3sywSjmhWRyEg%3D
- http://aq.#q.com/cn2/unionverify/unionverify_jump?ju############################
- '35.##0.72.216':443
- 'aq.#q.com':443
- DNS ASK i2.##etuku.com
- DNS ASK aq.#q.com
- DNS ASK oc##.#igicert.cn
- '%TEMP%\syslemnrwvl.exe'