Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\Ai5Ic1Vhx] 'ImagePath' = '<DRIVERS>\Ai5Ic1Vhx.sys'
- %TEMP%\21af0.tmp
- %TEMP%\22f25.tmp
- %TEMP%\234f3.tmp
- <DRIVERS>\Ai5Ic1Vhx.sys
- %TEMP%\21af0.tmp
- %TEMP%\22f25.tmp
- %TEMP%\234f3.tmp
- <DRIVERS>\Ai5Ic1Vhx.sys
- '12#.#25.114.144':80
- http://ba##u.com/ via 12#.#25.114.144
- DNS ASK ba##u.com