Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows menu' = '%TEMP%\<File name>.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\policies\Explorer\run] 'Messenger' = '%APPDATA%\IC3LOKPBZA.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'Messenger' = '%APPDATA%\IC3LOKPBZA.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Messenger' = '%APPDATA%\IC3LOKPBZA.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components\{53CDA24E-CA68-9EEC-0733-C079CE1F9C6E}] 'StubPath' = '%APPDATA%\IC3LOKPBZA.exe'
- [<HKCU>\SOFTWARE\Microsoft\Active Setup\Installed Components\{53CDA24E-CA68-9EEC-0733-C079CE1F9C6E}] 'StubPath' = '%APPDATA%\IC3LOKPBZA.exe'
- <Drive name for removable media>:\vbc.exe
- <Drive name for removable media>:\autorun.ini
- vbc.exe
- %TEMP%\<File name>.exe
- %TEMP%\vbc.exe
- <Drive name for removable media>:\vbc.exe
- <Drive name for removable media>:\autorun.ini
- from %TEMP%\vbc.exe to %APPDATA%\ic3lokpbza.exe
- '%TEMP%\vbc.exe'
- '%WINDIR%\syswow64\cmd.exe' /c REG ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile /v "DoNotAllowExceptions" /t REG_DWORD /d "0" /f' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c REG ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "%TEMP%\vbc.exe" /t REG_SZ /d "%TEMP%\vbc.exe:*:Enabled:W...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c REG ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "%APPDATA%\IC3LOKPBZA.exe" /t REG_SZ /d "%APPDATA%\IC3LOK...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c REG ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile /v "DoNotAllowExceptions" /t REG_DWORD /d "0" /f
- '%WINDIR%\syswow64\cmd.exe' /c REG ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "%TEMP%\vbc.exe" /t REG_SZ /d "%TEMP%\vbc.exe:*:Enabled:W...
- '%WINDIR%\syswow64\cmd.exe' /c REG ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "%APPDATA%\IC3LOKPBZA.exe" /t REG_SZ /d "%APPDATA%\IC3LOK...