Technical Information
- [<HKCU>\software\microsoft\windows\currentversion\run] 'BWcMwoko.exe' = '%HOMEPATH%\QQcsQcAA\BWcMwoko.exe'
- [<HKLM>\System\CurrentControlSet\Services\bUUIgIJT] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\bUUIgIJT] 'ImagePath' = '%ALLUSERSPROFILE%\xccAEEwY\FKIIUIQc.exe'
- 'bUUIgIJT' %ALLUSERSPROFILE%\xccAEEwY\FKIIUIQc.exe
- %HOMEPATH%\qqcsqcaa\bwcmwoko
- %ALLUSERSPROFILE%\gugggkmw\ooqcckyk
- %HOMEPATH%\qqcsqcaa\bwcmwoko.exe
- %ALLUSERSPROFILE%\xccaeewy\fkiiuiqc.exe
- %WINDIR%\syswow64\config\systemprofile\qqcsqcaa\bwcmwoko
- http://google.com/
- DNS ASK bl##k.io
- DNS ASK google.com
- ClassName: '' WindowName: 'OOQcckYk.exe'
- ClassName: '' WindowName: 'Microsoft Windows'
- '%HOMEPATH%\qqcsqcaa\bwcmwoko.exe'
- '%ALLUSERSPROFILE%\xccaeewy\fkiiuiqc.exe'