Technical Information
- [<HKLM>\System\CurrentControlSet\Services\pcidump] 'ImagePath' = '<DRIVERS>\pcidump.sys'
- 'AsyncMac' <DRIVERS>\AsyncMac.sys
- 'pcidump' <DRIVERS>\pcidump.sys
- '%WINDIR%\syswow64\taskkill.exe' /im ekrn.exe /f
- '%WINDIR%\syswow64\taskkill.exe' /im egui.exe /f
- '%WINDIR%\syswow64\net.exe' stop wscsvc
- '%WINDIR%\syswow64\net.exe' stop SharedAccess
- %WINDIR%\tete1175997t.dll
- %WINDIR%\syswow64\drivers\asyncmac.sys
- C:\autorun.inf
- C:\recycle.{645ff040-5081-101b-9f08-00aa002f954e}\rav32.exe
- %WINDIR%\extext1191067t.exe
- %WINDIR%\syswow64\drivers\pcidump.sys
- %WINDIR%\syswow64\scvhost.exe
- <Current directory>\afc90a.bat
- <Current directory>\321.aqq
- C:\autorun.inf
- %WINDIR%\syswow64\drivers\asyncmac.sys
- %WINDIR%\tete1175997t.dll
- %WINDIR%\syswow64\drivers\pcidump.sys
- <Current directory>\321.aqq
- ClassName: 'Notepad' WindowName: ''
- ClassName: '' WindowName: ''
- '%WINDIR%\extext1191067t.exe'
- '%WINDIR%\syswow64\notepad.exe' ' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c sc config ekrn start= disabled' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c taskkill.exe /im ekrn.exe /f' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c taskkill.exe /im egui.exe /f' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c net stop wscsvc' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c net stop SharedAccess' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c sc config sharedaccess start= disabled' (with hidden window)
- '%WINDIR%\extext1191067t.exe' ' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c afc90a.bat' (with hidden window)
- '%WINDIR%\syswow64\notepad.exe'
- '%WINDIR%\syswow64\cmd.exe' /c sc config ekrn start= disabled
- '%WINDIR%\syswow64\sc.exe' config ekrn start= disabled
- '%WINDIR%\syswow64\cmd.exe' /c taskkill.exe /im ekrn.exe /f
- '%WINDIR%\syswow64\cmd.exe' /c taskkill.exe /im egui.exe /f
- '%WINDIR%\syswow64\rundll32.exe' %WINDIR%\tete1175997t.dll testall
- '%WINDIR%\syswow64\cmd.exe' /c net stop wscsvc
- '%WINDIR%\syswow64\net1.exe' stop wscsvc
- '%WINDIR%\syswow64\cmd.exe' /c net stop SharedAccess
- '%WINDIR%\syswow64\net1.exe' stop SharedAccess
- '%WINDIR%\syswow64\cmd.exe' /c sc config sharedaccess start= disabled
- '%WINDIR%\syswow64\sc.exe' config sharedaccess start= disabled
- '%WINDIR%\syswow64\cmd.exe' /c afc90a.bat