Technical Information
- [<HKLM>\System\CurrentControlSet\Services\adprovider] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\adprovider] 'ImagePath' = '"%WINDIR%\SysWOW64\KBDFO\adprovider.exe"'
- 'adprovider' "%WINDIR%\SysWOW64\KBDFO\adprovider.exe"
- 'adprovider' %WINDIR%\SysWOW64\KBDFO\adprovider.exe
- from <Full path to file> to %WINDIR%\syswow64\kbdfo\adprovider.exe
- '22#.#47.142.214':80
- http://22#.#47.142.214/T69xozK/S7fQtTR4jSY/