Technical Information
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'Explorer.exe "%ALLUSERSPROFILE%\application data\Microsoft\KBDriver\kbsys.exe"'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'DirLock' = '%ALLUSERSPROFILE%\application data\Lambda\DirLock.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'LSAgent' = '%WINDIR%\lsass.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Win32' = '%WINDIR%\system.exe'
- %WINDIR%\tasks.exe
- %ALLUSERSPROFILE%\start menu\programs\startup\classified.exe
- <Drive name for removable media>:\classified.exe
- <Drive name for removable media>:\read1st.exe
- <Drive name for removable media>:\autorun.inf
- hidden files
- file extensions
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFolderOptions' = '00000001'
- System
- <SYSTEM32>\taskhost.exe
- firefox.exe
- <Current directory>\classified.exe
- %WINDIR%\syswow64\et-ee.exe
- %WINDIR%\syswow64\fi-fi.exe
- %WINDIR%\syswow64\fr-fr.exe
- %WINDIR%\syswow64\fxstmp.exe
- %WINDIR%\syswow64\grouppolicy.exe
- %WINDIR%\syswow64\grouppolicyusers.exe
- %WINDIR%\syswow64\he-il.exe
- %WINDIR%\syswow64\hr-hr.exe
- %WINDIR%\syswow64\ar-sa.exe
- %WINDIR%\syswow64\hu-hu.exe
- %WINDIR%\syswow64\ime.exe
- %WINDIR%\syswow64\inetsrv.exe
- %WINDIR%\syswow64\installshield.exe
- %WINDIR%\syswow64\it-it.exe
- %WINDIR%\syswow64\ja-jp.exe
- %WINDIR%\syswow64\ko-kr.exe
- %WINDIR%\syswow64\logfiles.exe
- %WINDIR%\syswow64\lt-lt.exe
- %WINDIR%\syswow64\en-us.exe
- %WINDIR%\syswow64\es-es.exe
- %WINDIR%\syswow64\en.exe
- %WINDIR%\syswow64\el-gr.exe
- %WINDIR%\syswow64\driverstore.exe
- %WINDIR%\syswow64\winnthlp2.exe
- C:\read1st.exe
- C:\autorun.inf
- D:\classified.exe
- D:\read1st.exe
- D:\autorun.inf
- %WINDIR%\lsass.exe
- %WINDIR%\syswow64\0409.exe
- %WINDIR%\syswow64\lv-lv.exe
- %WINDIR%\syswow64\icsxml.exe
- %WINDIR%\syswow64\advancedinstallers.exe
- %WINDIR%\syswow64\catroot.exe
- %WINDIR%\syswow64\catroot2.exe
- %WINDIR%\syswow64\com.exe
- %WINDIR%\syswow64\config.exe
- %WINDIR%\syswow64\cs-cz.exe
- %WINDIR%\syswow64\da-dk.exe
- %WINDIR%\syswow64\de-de.exe
- %WINDIR%\syswow64\drivers.exe
- %WINDIR%\syswow64\winnthlp1.exe
- %WINDIR%\syswow64\bg-bg.exe
- %WINDIR%\syswow64\pt-pt.exe
- %TEMP%\lwpfe6-lmfds6-i3vaj9-6wc5il-0trafr\2.exe
- %WINDIR%\syswow64\migwiz.exe
- %WINDIR%\syswow64\sysprep.exe
- %WINDIR%\syswow64\tasks.exe
- %WINDIR%\syswow64\th-th.exe
- %WINDIR%\syswow64\tr-tr.exe
- %WINDIR%\syswow64\uk-ua.exe
- %WINDIR%\syswow64\wbem.exe
- %WINDIR%\syswow64\wcn.exe
- %WINDIR%\syswow64\wdi.exe
- %WINDIR%\syswow64\manifeststore.exe
- %WINDIR%\syswow64\windowspowershell.exe
- %WINDIR%\syswow64\zh-cn.exe
- %WINDIR%\syswow64\zh-hk.exe
- %WINDIR%\syswow64\zh-tw.exe
- %WINDIR%\syswow64\classified.exe
- %WINDIR%\syswow64\winnthlp1\classified.exe
- %WINDIR%\syswow64\winnthlp2\classified.exe
- %TEMP%\iqjkaz-ogu2xs-e30662-8v3kd8-mk0l6v\2.exe
- %TEMP%\15bpnb-12berc-wo318g-kmvnxs-3af8z9\2.exe
- %WINDIR%\syswow64\sr-latn-cs.exe
- %WINDIR%\syswow64\sv-se.exe
- %WINDIR%\syswow64\sppui.exe
- %WINDIR%\syswow64\spp.exe
- %WINDIR%\syswow64\speech.exe
- %WINDIR%\syswow64\mui.exe
- %WINDIR%\syswow64\nb-no.exe
- %WINDIR%\syswow64\ndf.exe
- %WINDIR%\syswow64\networklist.exe
- %WINDIR%\syswow64\nl-nl.exe
- %WINDIR%\syswow64\oobe.exe
- %WINDIR%\syswow64\pl-pl.exe
- %WINDIR%\syswow64\printing_admin_scripts.exe
- %WINDIR%\syswow64\migration.exe
- %TEMP%\ofuwlx-ocvlpx-jyn862-7wfuve-qkzexv\2.exe
- %WINDIR%\syswow64\pt-br.exe
- %WINDIR%\syswow64\recovery.exe
- %WINDIR%\syswow64\restore.exe
- %WINDIR%\syswow64\ro-ro.exe
- %WINDIR%\syswow64\ru-ru.exe
- %WINDIR%\syswow64\setup.exe
- %WINDIR%\syswow64\sk-sk.exe
- %WINDIR%\syswow64\sl-si.exe
- %WINDIR%\syswow64\slmgr.exe
- %WINDIR%\syswow64\msdtc.exe
- %WINDIR%\syswow64\ras.exe
- %WINDIR%\syswow64\winrm.exe
- %ALLUSERSPROFILE%\application data\lambda\dirlock.exe
- %WINDIR%\syswow64.exe
- %ProgramFiles(x86)%\windows photo viewer.exe
- %ProgramFiles(x86)%\windows portable devices.exe
- %ProgramFiles(x86)%\windows sidebar.exe
- %ProgramFiles(x86)%\classified.exe
- %CommonProgramFiles(x86)%\adobe.exe
- %CommonProgramFiles(x86)%\java.exe
- %CommonProgramFiles(x86)%\microsoft shared.exe
- %CommonProgramFiles(x86)%\services.exe
- %CommonProgramFiles(x86)%.exe
- %CommonProgramFiles(x86)%\speechengines.exe
- %CommonProgramFiles(x86)%\system.exe
- %CommonProgramFiles(x86)%\classified.exe
- %WINDIR%\addins.exe
- %WINDIR%\appcompat.exe
- %WINDIR%\apppatch.exe
- %WINDIR%\boot.exe
- %WINDIR%\branding.exe
- %WINDIR%\csc.exe
- %ProgramFiles(x86)%\windows media player.exe
- %ProgramFiles(x86)%\windows nt.exe
- %ProgramFiles(x86)%\windows mail.exe
- %ProgramFiles(x86)%\windows defender.exe
- %ProgramFiles(x86)%\steam.exe
- C:\kms.exe
- C:\perflogs.exe
- C:\program files.exe
- C:\program files (x86).exe
- <Current directory>.exe
- C:\users.exe
- %WINDIR%.exe
- C:\classified.exe
- %WINDIR%\cursors.exe
- %CommonProgramFiles(x86)%\steam.exe
- %ProgramFiles(x86)%\adobe.exe
- %ProgramFiles(x86)%\microsoft.exe
- %ProgramFiles(x86)%\microsoft analysis services.exe
- %ProgramFiles(x86)%\microsoft office.exe
- %ProgramFiles(x86)%\microsoft visual studio 8.exe
- %ProgramFiles(x86)%\microsoft.net.exe
- %ProgramFiles(x86)%\msbuild.exe
- %ProgramFiles(x86)%\opera.exe
- %ProgramFiles(x86)%\reference assemblies.exe
- <PATH_SAMPLE>\classified.exe
- %ProgramFiles(x86)%\internet explorer.exe
- %WINDIR%\microsoft.net.exe
- %WINDIR%\shutdown.dll
- %WINDIR%\digitallocker.exe
- %WINDIR%\security.exe
- %WINDIR%\serviceprofiles.exe
- %WINDIR%\servicing.exe
- %WINDIR%\setup.exe
- %WINDIR%\shellnew.exe
- %WINDIR%\softwaredistribution.exe
- %WINDIR%\speech.exe
- %WINDIR%\system.exe
- %WINDIR%\debug.exe
- <SYSTEM32>.exe
- %WINDIR%\tapi.exe
- %WINDIR%\temp.exe
- %WINDIR%\tracing.exe
- %WINDIR%\twain_32.exe
- %WINDIR%\vss.exe
- %WINDIR%\web.exe
- %WINDIR%\winsxs.exe
- %WINDIR%\classified.exe
- %WINDIR%\schcache.exe
- %WINDIR%\schemas.exe
- %WINDIR%\resources.exe
- %WINDIR%\rescache.exe
- %WINDIR%\remotepackages.exe
- %WINDIR%\ehome.exe
- %WINDIR%\en-us.exe
- %WINDIR%\globalization.exe
- %WINDIR%\help.exe
- %WINDIR%\ime.exe
- %WINDIR%\inf.exe
- %WINDIR%\l2schemas.exe
- %WINDIR%\livekernelreports.exe
- %WINDIR%\diagnostics.exe
- %ALLUSERSPROFILE%\application data\microsoft\kbdriver\kbsys.exe
- %WINDIR%\logs.exe
- %WINDIR%\offline web pages.exe
- %WINDIR%\panther.exe
- %WINDIR%\pchealth.exe
- %WINDIR%\performance.exe
- %WINDIR%\pla.exe
- %WINDIR%\policydefinitions.exe
- %WINDIR%\prefetch.exe
- %WINDIR%\registration.exe
- %WINDIR%\downloaded program files.exe
- %WINDIR%\modemlogs.exe
- %TEMP%\oyim2z-vou4os-lb08x3-f33m48-ss0nyv\2.exe
- C:\read1st.exe
- C:\autorun.inf
- D:\read1st.exe
- D:\autorun.inf
- <Drive name for removable media>:\read1st.exe
- <Drive name for removable media>:\autorun.inf
- %WINDIR%\system.exe
- %WINDIR%\syswow64\sv-se.exe
- %WINDIR%\syswow64\sr-latn-cs.exe
- %WINDIR%\syswow64\sppui.exe
- %WINDIR%\syswow64\spp.exe
- %WINDIR%\syswow64\speech.exe
- %WINDIR%\syswow64\slmgr.exe
- %WINDIR%\syswow64\tasks.exe
- %WINDIR%\syswow64\sysprep.exe
- %WINDIR%\syswow64\setup.exe
- %WINDIR%\syswow64\ru-ru.exe
- %WINDIR%\syswow64\ro-ro.exe
- %WINDIR%\syswow64\restore.exe
- %WINDIR%\syswow64\recovery.exe
- %WINDIR%\syswow64\ras.exe
- %WINDIR%\syswow64\sl-si.exe
- %WINDIR%\syswow64\hu-hu.exe
- %WINDIR%\syswow64\th-th.exe
- %WINDIR%\winsxs.exe
- <SYSTEM32>.exe
- %WINDIR%\servicing.exe
- %WINDIR%\rescache.exe
- %WINDIR%\diagnostics.exe
- %WINDIR%\boot.exe
- %WINDIR%\syswow64\zh-tw.exe
- %WINDIR%\syswow64\zh-hk.exe
- %WINDIR%\syswow64\zh-cn.exe
- %WINDIR%\syswow64\winrm.exe
- %WINDIR%\syswow64\windowspowershell.exe
- %WINDIR%\syswow64\wdi.exe
- %WINDIR%\syswow64\wcn.exe
- %WINDIR%\syswow64\wbem.exe
- %WINDIR%\syswow64\uk-ua.exe
- %WINDIR%\syswow64\pt-pt.exe
- %WINDIR%\syswow64\sk-sk.exe
- %WINDIR%\syswow64\pt-br.exe
- %WINDIR%\syswow64\printing_admin_scripts.exe
- %WINDIR%\syswow64\pl-pl.exe
- %WINDIR%\syswow64\en-us.exe
- %WINDIR%\syswow64\grouppolicy.exe
- %WINDIR%\syswow64\fxstmp.exe
- %WINDIR%\syswow64\fr-fr.exe
- %WINDIR%\syswow64\fi-fi.exe
- %WINDIR%\syswow64\et-ee.exe
- %WINDIR%\syswow64\es-es.exe
- %WINDIR%\syswow64\en.exe
- %WINDIR%\syswow64\he-il.exe
- %WINDIR%\syswow64\el-gr.exe
- %WINDIR%\syswow64\driverstore.exe
- %WINDIR%\syswow64\drivers.exe
- %WINDIR%\syswow64\advancedinstallers.exe
- %ALLUSERSPROFILE%\application data\microsoft\kbdriver\kbsys.exe
- %ALLUSERSPROFILE%\start menu\programs\startup\classified.exe
- %WINDIR%\syswow64\winnthlp1.exe
- %WINDIR%\syswow64\tr-tr.exe
- %WINDIR%\syswow64\hr-hr.exe
- %WINDIR%\syswow64\ja-jp.exe
- %WINDIR%\syswow64\grouppolicyusers.exe
- %WINDIR%\syswow64\oobe.exe
- %WINDIR%\syswow64\nl-nl.exe
- %WINDIR%\syswow64\networklist.exe
- %WINDIR%\syswow64\ndf.exe
- %WINDIR%\syswow64\nb-no.exe
- %WINDIR%\syswow64\mui.exe
- %WINDIR%\syswow64\msdtc.exe
- %WINDIR%\syswow64\migwiz.exe
- %WINDIR%\syswow64\migration.exe
- %WINDIR%\syswow64\manifeststore.exe
- %WINDIR%\syswow64\lv-lv.exe
- %WINDIR%\syswow64\lt-lt.exe
- %WINDIR%\syswow64\logfiles.exe
- %WINDIR%\syswow64\ko-kr.exe
- %WINDIR%\syswow64\icsxml.exe
- %WINDIR%\syswow64\winnthlp2.exe
- %WINDIR%\system.exe
- %WINDIR%\syswow64\sv-se.exe
- %WINDIR%\syswow64\sr-latn-cs.exe
- %WINDIR%\syswow64\sppui.exe
- %WINDIR%\syswow64\spp.exe
- %WINDIR%\syswow64\speech.exe
- %WINDIR%\syswow64\slmgr.exe
- %WINDIR%\syswow64\sysprep.exe
- %WINDIR%\syswow64\sl-si.exe
- %WINDIR%\syswow64\setup.exe
- %WINDIR%\syswow64\ru-ru.exe
- %WINDIR%\syswow64\ro-ro.exe
- %WINDIR%\syswow64\restore.exe
- %WINDIR%\syswow64\recovery.exe
- %WINDIR%\syswow64\ras.exe
- %WINDIR%\syswow64\sk-sk.exe
- %WINDIR%\syswow64\tasks.exe
- %WINDIR%\syswow64\th-th.exe
- %WINDIR%\syswow64\tr-tr.exe
- %WINDIR%\winsxs.exe
- <SYSTEM32>.exe
- %WINDIR%\servicing.exe
- %WINDIR%\rescache.exe
- %WINDIR%\diagnostics.exe
- %WINDIR%\boot.exe
- %WINDIR%\syswow64\zh-tw.exe
- %WINDIR%\syswow64\zh-hk.exe
- %WINDIR%\syswow64\zh-cn.exe
- %WINDIR%\syswow64\winrm.exe
- %WINDIR%\syswow64\windowspowershell.exe
- %WINDIR%\syswow64\wdi.exe
- %WINDIR%\syswow64\wcn.exe
- %WINDIR%\syswow64\wbem.exe
- %WINDIR%\syswow64\uk-ua.exe
- %WINDIR%\syswow64\pt-pt.exe
- %WINDIR%\syswow64\winnthlp1.exe
- %WINDIR%\syswow64\pt-br.exe
- %WINDIR%\syswow64\pl-pl.exe
- %WINDIR%\syswow64\grouppolicyusers.exe
- %WINDIR%\syswow64\grouppolicy.exe
- %WINDIR%\syswow64\fxstmp.exe
- %WINDIR%\syswow64\fr-fr.exe
- %WINDIR%\syswow64\fi-fi.exe
- %WINDIR%\syswow64\et-ee.exe
- %WINDIR%\syswow64\he-il.exe
- %WINDIR%\syswow64\es-es.exe
- %WINDIR%\syswow64\en.exe
- %WINDIR%\syswow64\el-gr.exe
- %WINDIR%\syswow64\driverstore.exe
- %WINDIR%\syswow64\drivers.exe
- %WINDIR%\syswow64\advancedinstallers.exe
- %ALLUSERSPROFILE%\application data\microsoft\kbdriver\kbsys.exe
- %WINDIR%\syswow64\en-us.exe
- %WINDIR%\syswow64\hr-hr.exe
- %WINDIR%\syswow64\hu-hu.exe
- %WINDIR%\syswow64\icsxml.exe
- %WINDIR%\syswow64\oobe.exe
- %WINDIR%\syswow64\nl-nl.exe
- %WINDIR%\syswow64\networklist.exe
- %WINDIR%\syswow64\ndf.exe
- %WINDIR%\syswow64\nb-no.exe
- %WINDIR%\syswow64\mui.exe
- %WINDIR%\syswow64\msdtc.exe
- %WINDIR%\syswow64\migwiz.exe
- %WINDIR%\syswow64\migration.exe
- %WINDIR%\syswow64\manifeststore.exe
- %WINDIR%\syswow64\lv-lv.exe
- %WINDIR%\syswow64\lt-lt.exe
- %WINDIR%\syswow64\logfiles.exe
- %WINDIR%\syswow64\ko-kr.exe
- %WINDIR%\syswow64\ja-jp.exe
- %WINDIR%\syswow64\printing_admin_scripts.exe
- %WINDIR%\syswow64\winnthlp2.exe
- '%ALLUSERSPROFILE%\application data\lambda\dirlock.exe'
- '%TEMP%\ofuwlx-ocvlpx-jyn862-7wfuve-qkzexv\2.exe'
- '%WINDIR%\syswow64\winnthlp1.exe'
- '%WINDIR%\syswow64\winnthlp2.exe'
- '%WINDIR%\lsass.exe'
- '%TEMP%\iqjkaz-ogu2xs-e30662-8v3kd8-mk0l6v\2.exe'
- '%TEMP%\15bpnb-12berc-wo318g-kmvnxs-3af8z9\2.exe'
- '%TEMP%\lwpfe6-lmfds6-i3vaj9-6wc5il-0trafr\2.exe'
- '%TEMP%\oyim2z-vou4os-lb08x3-f33m48-ss0nyv\2.exe'
- '%WINDIR%\syswow64\explorer.exe' <PATH_SAMPLE>
- '%WINDIR%\syswow64\explorer.exe' %WINDIR%\SysWOW64\winnthlp1
- '%WINDIR%\syswow64\explorer.exe' %WINDIR%\SysWOW64\winnthlp2
- '%ALLUSERSPROFILE%\application data\lambda\dirlock.exe' ' (with hidden window)
- '%TEMP%\ofuwlx-ocvlpx-jyn862-7wfuve-qkzexv\2.exe' ' (with hidden window)
- '%WINDIR%\syswow64\winnthlp1.exe' ' (with hidden window)
- '%WINDIR%\syswow64\winnthlp2.exe' ' (with hidden window)
- '%WINDIR%\lsass.exe' ' (with hidden window)
- '%TEMP%\iqjkaz-ogu2xs-e30662-8v3kd8-mk0l6v\2.exe' ' (with hidden window)
- '%TEMP%\15bpnb-12berc-wo318g-kmvnxs-3af8z9\2.exe' ' (with hidden window)
- '%TEMP%\lwpfe6-lmfds6-i3vaj9-6wc5il-0trafr\2.exe' ' (with hidden window)
- '%TEMP%\oyim2z-vou4os-lb08x3-f33m48-ss0nyv\2.exe' ' (with hidden window)
- '%TEMP%\vzi887-3jiz5z-2fjn9z-y2bbq4-m03wfg\2.exe' ' (with hidden window)
- '%TEMP%\r5d1sb-sw3z7a-pdjwye-d60qxp-73fwtw\2.exe' ' (with hidden window)
- '%TEMP%\dhvhni-l2v8ja-lyvwoa-glnk5f-4jf5tr\2.exe' ' (with hidden window)
- '%TEMP%\pwcdq9-rhqkf7-y71210-nu76ab-imakhg\2.exe' ' (with hidden window)