Technical Information
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'system' = '<SYSTEM32>\system.exe'
- [<HKLM>\System\CurrentControlSet\Services\Driver] 'ImagePath' = 'C:\Driver.sys'
- 'Driver' C:\Driver.sys
- C:\driver.sys
- C:\pci.sys
- %WINDIR%\syswow64\klg.dll
- %WINDIR%\temp\udd4e3e.tmp
- %WINDIR%\syswow64\ipi.dll
- %TEMP%\1281189.tmp
- %WINDIR%\temp\udd4e3e.tmp
- C:\pci.sys
- C:\driver.sys
- from <Full path to file> to %WINDIR%\syswow64\system.exe
- '%WINDIR%\syswow64\sc.exe' stop 360rp' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' delete McSysmon' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' delete mcmscsvc' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' stop McSysmon' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' stop mcmscsvc' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' delete McODS' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' delete McShield' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' stop McODS' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' stop McShield' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' delete McProxy' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' stop McProxy' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' stop MpfService' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' delete MpfService' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' delete McNASvc' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' stop McNASvc' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' delete RsRavMon' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' stop RsRavMon' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' delete 360rp' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' stop ekrn' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' delete ekrn' (with hidden window)
- '%WINDIR%\syswow64\rundll32.exe' <SYSTEM32>\klg.dll Execute
- '%WINDIR%\syswow64\sc.exe' stop ekrn
- '%WINDIR%\syswow64\sc.exe' delete McSysmon
- '%WINDIR%\syswow64\sc.exe' delete mcmscsvc
- '%WINDIR%\syswow64\sc.exe' stop McSysmon
- '%WINDIR%\syswow64\sc.exe' stop mcmscsvc
- '%WINDIR%\syswow64\sc.exe' delete McODS
- '%WINDIR%\syswow64\sc.exe' delete McShield
- '%WINDIR%\syswow64\sc.exe' stop McODS
- '%WINDIR%\syswow64\sc.exe' stop McShield
- '%WINDIR%\syswow64\sc.exe' delete McProxy
- '%WINDIR%\syswow64\sc.exe' stop McProxy
- '%WINDIR%\syswow64\sc.exe' stop MpfService
- '%WINDIR%\syswow64\sc.exe' delete MpfService
- '%WINDIR%\syswow64\sc.exe' delete McNASvc
- '%WINDIR%\syswow64\sc.exe' stop McNASvc
- '%WINDIR%\syswow64\sc.exe' delete RsRavMon
- '%WINDIR%\syswow64\sc.exe' stop RsRavMon
- '%WINDIR%\syswow64\sc.exe' delete 360rp
- '%WINDIR%\syswow64\sc.exe' stop 360rp
- '%WINDIR%\syswow64\sc.exe' delete ekrn
- '%WINDIR%\syswow64\rundll32.exe' <SYSTEM32>\ipi.dll Execute