Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] '3100924223' = '%ALLUSERSPROFILE%\msibszk.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ec525f4' = '%APPDATA%\ec525f4.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ec525f' = 'C:\ec525f4\ec525f4.exe'
- %HOMEPATH%\Start Menu\Programs\Startup\ec525f4.exe
- hidden files
- Windows Update
- Windows Security Center
- System Restore (SR)
- User Account Control (UAC)
- Windows Action Center
- Hides taskbar notifications
- '%TEMP%\3.tmp'
- '<SYSTEM32>\msiexec.exe'
- '<SYSTEM32>\svchost.exe' netsvcs
- '<SYSTEM32>\locator.exe'
- '%TEMP%\2.tmp'
- '%WINDIR%\explorer.exe'
- <SYSTEM32>\svchost.exe
- C:\ec525f4\ec525f4.exe
- %APPDATA%\ec525f4.exe
- %TEMP%\2.tmp
- %TEMP%\3.tmp
- %ALLUSERSPROFILE%\msibszk.exe
- from %TEMP%\3.tmp to %ALLUSERSPROFILE%\msibszk.exe
- '1t##buy.com':80
- 'fl####rguides.com':80
- 'ba###ttech.com':80
- 'av###esurs.net':80
- 'po##eva.com':80
- 'te###rtone.com':80
- 'ch###log.net':80
- 'it####xation.com':80
- 'pr####ioncheck.com':80
- 'an##hin.org':80
- 'pc##ter.com':80
- 'ja###gia.net':80
- 'lz###ent.com':80
- 'ph###bic.com':80
- 'da###ngroup.com':80
- 'cu###yip.com':80
- 'fl##yak.org':80
- 'hg###ting.net':80
- 'my####rnalip.com':80
- '20#.#6.232.182':80
- 'ip##ddr.es':80
- 'sh####ngblue.net':80
- 'ci####ineral.com':80
- 'hi##ix.net':80
- 'ho##ar.info':80
- 'et####etport.com':80
- 'sn##ns.org':80
- 'le##m.com':80
- 'ri##jel.com':80
- http://cu###yip.com/
- http://my####rnalip.com/raw
- http://ip##ddr.es/
- http://fl####rguides.com/web-content/img1.php?z=############
- http://ba###ttech.com/renew/img2.php?a=############
- http://ja###gia.net/img5.php?q=############
- http://ch###log.net/img5.php?l=############
- http://av###esurs.net/img4.php?g=############
- http://1t##buy.com/img2.php?e=############
- http://it####xation.com/img2.php?z=############
- http://pr####ioncheck.com/img5.php?b=############
- http://an##hin.org/misc/img5.php?m=############
- http://lz###ent.com/img4.php?d=############
- http://ph###bic.com/img1.php?w=############
- http://pc##ter.com/img4.php?e=############
- http://le##m.com/img1.php?c=############
- http://ri##jel.com/img4.php?r=############
- http://et####etport.com/img3.php?l=############
- http://fl##yak.org/img4.php?l=############
- http://hg###ting.net/img1.php?c=############
- http://sn##ns.org/img4.php?s=############
- http://da###ngroup.com/img1.php?o=############
- http://po##eva.com/img4.php?e=############
- http://te###rtone.com/img4.php?j=############
- http://ci####ineral.com/img/img2.php?w=############
- http://hi##ix.net/img3.php?w=############
- http://ho##ar.info/img2.php?t=############
- DNS ASK 1t##buy.com
- DNS ASK av###esurs.net
- DNS ASK ba###ttech.com
- DNS ASK fl####rguides.com
- DNS ASK po##eva.com
- DNS ASK da###ngroup.com
- DNS ASK ch###log.net
- DNS ASK te###rtone.com
- DNS ASK pr####ioncheck.com
- DNS ASK it####xation.com
- DNS ASK bu###ova.com
- DNS ASK an##hin.org
- DNS ASK lz###ent.com
- DNS ASK ja###gia.net
- DNS ASK pc##ter.com
- DNS ASK ph###bic.com
- DNS ASK ho##ar.info
- DNS ASK my####rnalip.com
- DNS ASK cu###yip.com
- DNS ASK fl##yak.org
- DNS ASK ip##ddr.es
- DNS ASK eu####.pool.ntp.org
- DNS ASK up####.microsoft.com
- DNS ASK sh####ngblue.net
- DNS ASK et####etport.com
- DNS ASK ci####ineral.com
- DNS ASK hi##ix.net
- DNS ASK ri##jel.com
- DNS ASK hg###ting.net
- DNS ASK sn##ns.org
- DNS ASK le##m.com
- 'localhost':1037
- 'eu####.pool.ntp.org':123