Technical Information
- [HKLM\System\CurrentControlSet\Services\2041sMtXb] 'ImagePath' = '%WINDIR%\Fonts\sCCFw.sys'
- [HKLM\System\CurrentControlSet\Services\2041pQuEb] 'ImagePath' = '%WINDIR%\Fonts\sCCFw.sys'
- '2041sMtXb' %WINDIR%\Fonts\sCCFw.sys
- '2041pQuEb' %WINDIR%\Fonts\sCCFw.sys
- %TEMP%\sccfw.sys
- %WINDIR%\fonts\sccfw.sys
- %WINDIR%\temp\udde0dc.tmp
- %WINDIR%\temp\udde8f8.tmp
- %WINDIR%\temp\udd85e7.tmp
- %TEMP%\sccfw.sys
- %WINDIR%\temp\udde0dc.tmp
- %WINDIR%\temp\udde8f8.tmp
- %WINDIR%\temp\udd85e7.tmp
- %TEMP%\sccfw.sys
- '43.##2.103.18':80
- '13#.#75.221.3':8089
- '13#.#75.221.3':19738
- http://43.##2.103.18/SYSSS/SSDTHook_Communicate.txt
- http://43.##2.103.18/SYSSS/reg.txt
- http://43.##2.103.18/SYSSS/Driver_01.sys
- http://43.##2.103.18/SYSSS/Driver_02.sys
- '13#.#75.221.3':8089
- '13#.#75.221.3':19738