Technical Information
- [HKLM\SYSTEM\CurrentControlSet\Services\wanarp] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\RasMan] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\Please Input Service Name] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\Please Input Service Name] 'ImagePath' = '<SYSTEM32>\svchost.exe -k imgsvc'
- 'Please Input Service Name' <SYSTEM32>\svchost.exe -k imgsvc
- %TEMP%\rarsfx0\uharc.exe
- %TEMP%\rarsfx0\file.uha
- %TEMP%\rarsfx0\ms.exe
- C:\1078600.dll
- C:\nt_path.jpg
- %WINDIR%\inf\netsstpa.pnf
- %WINDIR%\inf\netrasa.pnf
- C:\net-temp.ini
- %WINDIR%\filename.jpg
- DNS ASK qw#####523.f3322.org
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\rarsfx0\uharc.exe' e file.uha
- '%TEMP%\rarsfx0\ms.exe'