Process Changes Creates these mutexes:
Network Connections Attempts to connect with HTTP to:
• http://www.bpfq02 .com
• http://www.inform1ongung .info
• http://www.g1ikddcvns3sdsal .info
• http://www.f5ds1jkkk4d .info
• http://www.lukki6dnd2kdnc .info
• http://www.h7smcnr1wlsdn34fgv .info
• http://wnt: KUKUww.hkukud123ncs .info
• http://www.kukutrustnet .info
• http://www.kukutrustnet7 .info
• http://www.kukutrustnet666 .info/[...]_nrl
Registry Modifications Sets these values:
• HKLM\System\CurrentControlSet\Services\NdisFileServices32
Type = 00000001
• HKLM\System\CurrentControlSet\Services\NdisFileServices32
Start = 00000002
• HKLM\System\CurrentControlSet\Services\NdisFileServices32
ErrorControl = 00000001
• HKLM\System\CurrentControlSet\Services\NdisFileServices32
ImagePath = \??\C:\WINDOWS\system32\drivers\ekkkjn.sys
• [Launchpoint: Service]
• HKLM\System\CurrentControlSet\Services\NdisFileServices32
DisplayName = NdisFileServices32
• HKLM\System\CurrentControlSet\Services\NdisFileServices32\Security
Security = \x01\x00\x14\x80\x90\x00\x00\x00\x9C\x00\x00\x00\x14\x00\x00\x00\x30\x00\x00\x00\x02\x00\x1C\x00\x01\x00\x00\x00\x02\x80\x14\x00\xFF\x01\x0F\x00\x01\x01\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x02\x00\x60\x00\x04\x00\x00\x00\x00\x00\x14\x00\xFD\x01\x02\x00\x01\x01\x00\x00\x00\x00\x00\x05\x12\x00\x00\x00\x00\x00\x18\x00\xFF\x01\x0F\x00\x01\x02\x00\x00\x00\x00\x00\x05\x20\x00\x00\x00\x20\x02\x00\x00\x00\x00\x14\x00\x8D\x01\x02\x00\x01\x01\x00\x00\x00\x00\x00\x05\x0B\x00\x00\x00\x00\x00\x18\x00\xFD\x01\x02\x00\x01\x02\x00\x00\x00\x00\x00\x05\x20\x00\x00\x00\x23\x02\x00\x00\x01\x01\x00\x00\x00\x00\x00\x05\x12\x00\x00\x00\x01\x01\x00\x00\x00\x00\x00\x05\x12\x00\x00\x00
• HKLM\System\CurrentControlSet\Services\ALG
DeleteFlag = 00000001
• HKLM\System\CurrentControlSet\Services\ALG
Start = 00000004
• HKLM\System\CurrentControlSet\Services\bdss
DeleteFlag = 00000001
• HKLM\System\CurrentControlSet\Services\bdss
Start = 00000004
• HKLM\System\CurrentControlSet\Services\F-Secure Gatekeeper Handler Starter
DeleteFlag = 00000001
• HKLM\System\CurrentControlSet\Services\F-Secure Gatekeeper Handler Starter
Start = 00000004
• HKLM\System\CurrentControlSet\Services\navapsvc
DeleteFlag = 00000001
• HKLM\System\CurrentControlSet\Services\navapsvc
Start = 00000004
• HKLM\System\CurrentControlSet\Services\AVP
DeleteFlag = 00000001
• HKLM\System\CurrentControlSet\Services\AVP
Start = 00000004
• HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings
GlobalUserOffline = 00000000
• HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
shell = Explorer.exe
[Launchpoint: RunOnce]
Deletes these values:
• HKLM\System\CurrentControlSet\Control\SafeBoot\AlternateShell
• HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt\ [Launchpoint: Safe mode (minimal)]
• HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\Base\ [Launchpoint: Safe mode (minimal)]
• HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender\ [Launchpoint: Safe mode (minimal)]
• HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system\ [Launchpoint: Safe mode (minimal)]
• HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc\ [Launchpoint: Safe mode (minimal)]
• HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch\ [Launchpoint: Safe mode (minimal)]
• HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\dmadmin\ [Launchpoint: Safe mode (minimal)]
• HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\dmboot.sys\ [Launchpoint: Safe mode (minimal)]
• HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\dmio.sys\ [Launchpoint: Safe mode (minimal)]
• HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\dmload.sys\ [Launchpoint: Safe mode (minimal)]
• HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\dmserver\ [Launchpoint: Safe mode (minimal)]
• HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\EventLog\ [Launchpoint: Safe mode (minimal)]
• HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\File system\ [Launchpoint: Safe mode (minimal)]
• HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\Filter\ [Launchpoint: Safe mode (minimal)]
• HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc\ [Launchpoint: Safe mode (minimal)]
• HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon\ [Launchpoint: Safe mode (minimal)]
• HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration\ [Launchpoint: Safe mode (minimal)]
• HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay\ [Launchpoint: Safe mode (minimal)]
• HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter\ [Launchpoint: Safe mode (minimal)]
• HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk\ [Launchpoint: Safe mode (minimal)]
• HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs\ [Launchpoint: Safe mode (minimal)]
• HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class\ [Launchpoint: Safe mode (minimal)]
• HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys\ [Launchpoint: Safe mode (minimal)]
• HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys\ [Launchpoint: Safe mode (minimal)]