Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,"%TEMP%\rknrl.vbs"'
- [<HKCU>\software\microsoft\windows\currentversion\run] 'winstart' = 'wscript.exe //B "%TEMP%\rknrl.vbs"'
- [<HKLM>\software\microsoft\windows\currentversion\run] 'winstart' = 'wscript.exe //B "%TEMP%\rknrl.vbs"'
- %APPDATA%\microsoft\windows\start menu\programs\startup\rknrl.vbs
- [<HKLM>\System\CurrentControlSet\Services\RemoteAccess] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\RemoteAccess] 'ImagePath' = '<SYSTEM32>\wscript.exe //B C:\autoexec.vbs'
- <Drive name for removable media>:\recycl\rkrl.vbs
- '%TEMP%\explorer.exe' //B "%TEMP%\winstart.vbs"
- '%WINDIR%\temp\svchost.exe' //B "%WINDIR%\TEMP\winstart.vbs"
- <SYSTEM32>\wscript.exe
- %TEMP%\winstart.vbs
- %TEMP%\rknrl.reg
- %TEMP%\explorer.exe
- C:\autoexec.vbs
- %WINDIR%\temp\rknrl.tmp
- %TEMP%\rknrl.vbs
- %WINDIR%\temp\winstart.vbs
- %WINDIR%\temp\svchost.exe
- C:\autoexec.vbs
- %TEMP%\rknrl.reg
- 'ai########orld.airobotheworld.com':80
- DNS ASK ai#####heworld.gicp.net
- DNS ASK ai########orld.airobotheworld.com
- DNS ASK ai#####heworld.3322.org
- DNS ASK ai#######world.ai-robot0.com
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- '<SYSTEM32>\wscript.exe' //B C:\autoexec.vbs
- '<SYSTEM32>\cmd.exe' /c regedit /s /q %TEMP%\rknrl.reg' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c sc stop RemoteAccess' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c sc config RemoteAccess binpath= "<SYSTEM32>\wscript.exe //B C:\autoexec.vbs" start= auto' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c sc start RemoteAccess' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c regedit /s /q %TEMP%\rknrl.reg
- '%WINDIR%\regedit.exe' /s /q %TEMP%\rknrl.reg
- '<SYSTEM32>\cmd.exe' /c sc stop RemoteAccess
- '<SYSTEM32>\cmd.exe' /c sc config RemoteAccess binpath= "<SYSTEM32>\wscript.exe //B C:\autoexec.vbs" start= auto
- '<SYSTEM32>\cmd.exe' /c sc start RemoteAccess
- '<SYSTEM32>\sc.exe' stop RemoteAccess
- '<SYSTEM32>\sc.exe' config RemoteAccess binpath= "<SYSTEM32>\wscript.exe //B C:\autoexec.vbs" start= auto
- '<SYSTEM32>\sc.exe' start RemoteAccess