Technical Information
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows] 'AppInit_DLLs' = ' msji449c14b7.dll'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'tserv' = '%WINDIR%\tserv.exe s'
- %WINDIR%\tserv.exe
- <Current directory>\8c97.tmp
- %WINDIR%\tserv.wax
- 'ww##.###esunjerinkas.com':80
- 'mt##.##0.yahoodns.net':25
- 'alt1.gmail-smtp-in.l.google.com':25
- 'ho#########.olc.protection.outlook.com':25
- DNS ASK ya##o.com
- DNS ASK ww##.###esunjerinkas.com
- DNS ASK mt##.##0.yahoodns.net
- DNS ASK gm##l.com
- DNS ASK alt4.gmail-smtp-in.l.google.com
- DNS ASK gmail-smtp-in.l.google.com
- DNS ASK alt2.gmail-smtp-in.l.google.com
- DNS ASK alt1.gmail-smtp-in.l.google.com
- DNS ASK alt3.gmail-smtp-in.l.google.com
- DNS ASK ho##ail.com
- DNS ASK ho#########.olc.protection.outlook.com
- '%WINDIR%\tserv.exe' s
- '%WINDIR%\syswow64\notepad.exe' <Current directory>\8C97.tmp