Technical Information
- <SYSTEM32>\bdeuisrv.exe
- %WINDIR%\windowsshell6155.log
- %WINDIR%\windowssystemupdate505.log
- '47.#8.35.46':36281
- '<LOCALNET>..42.0':51420
- '<LOCALNET>..42.1':51420
- '<LOCALNET>..42.3':51420
- '<LOCALNET>..42.5':51420
- '<LOCALNET>..42.4':51420
- '<LOCALNET>..42.6':51420
- '<LOCALNET>..42.2':51420
- '<LOCALNET>..42.7':51420
- '<LOCALNET>..42.9':51420
- '<LOCALNET>..42.10':51420
- '<LOCALNET>..42.20':51420
- '<LOCALNET>..42.18':51420
- '<LOCALNET>..42.12':51420
- '<LOCALNET>..42.24':51420
- '<LOCALNET>..42.14':51420
- '<LOCALNET>..42.26':51420
- '<LOCALNET>..42.8':51420
- '<LOCALNET>..42.16':51420
- '<LOCALNET>..42.22':51420
- '<LOCALNET>..42.11':51420
- '<LOCALNET>..42.13':51420
- '<LOCALNET>..42.15':51420
- '<LOCALNET>..42.17':51420
- '<LOCALNET>..42.19':51420
- '<LOCALNET>..42.21':51420
- '<LOCALNET>..42.23':51420
- '<LOCALNET>..42.25':51420
- '<LOCALNET>..42.27':51420
- '<LOCALNET>..42.29':51420
- '<LOCALNET>..42.28':51420
- '<LOCALNET>..42.32':51420
- '<LOCALNET>..42.36':51420
- '<LOCALNET>..42.38':51420
- '<LOCALNET>..42.40':51420
- '<LOCALNET>..42.37':51420
- '<LOCALNET>..42.39':51420
- '<LOCALNET>..42.35':51420
- '<LOCALNET>..42.33':51420
- '<LOCALNET>..42.34':51420
- '<LOCALNET>..42.42':51420
- '<LOCALNET>..42.44':51420
- '<LOCALNET>..42.46':51420
- '<LOCALNET>..42.50':51420
- '<LOCALNET>..42.52':51420
- '<LOCALNET>..42.54':51420
- '<LOCALNET>..42.56':51420
- '<LOCALNET>..42.58':51420
- '<LOCALNET>..42.60':51420
- '<LOCALNET>..42.62':51420
- '<LOCALNET>..42.66':51420
- '<LOCALNET>..42.70':51420
- '<LOCALNET>..42.72':51420
- '<LOCALNET>..42.74':51420
- '<LOCALNET>..42.76':51420
- '<LOCALNET>..42.78':51420
- '<LOCALNET>..42.80':51420
- '<LOCALNET>..42.84':51420
- '<LOCALNET>..42.86':51420
- '<LOCALNET>..42.90':51420
- '<LOCALNET>..42.92':51420
- '<LOCALNET>..42.96':51420
- '<LOCALNET>..42.100':51420
- '<LOCALNET>..42.102':51420
- '<LOCALNET>..42.104':51420
- '<LOCALNET>..42.106':51420
- '<LOCALNET>..42.108':51420
- '<LOCALNET>..42.110':51420
- '<LOCALNET>..42.41':51420
- '<LOCALNET>..42.43':51420
- '<LOCALNET>..42.45':51420
- '<LOCALNET>..42.47':51420
- '<LOCALNET>..42.64':51420
- '<LOCALNET>..42.98':51420
- '<LOCALNET>..42.49':51420
- '<LOCALNET>..42.51':51420
- '<LOCALNET>..42.53':51420
- '<LOCALNET>..42.55':51420
- '<LOCALNET>..42.82':51420
- '<LOCALNET>..42.30':51420
- '<LOCALNET>..42.94':51420
- '<LOCALNET>..42.48':51420
- '<LOCALNET>..42.68':51420
- '<LOCALNET>..42.114':51420
- '<LOCALNET>..42.116':51420
- '<LOCALNET>..42.88':51420
- '<LOCALNET>..42.120':51420
- '<LOCALNET>..42.122':51420
- '<LOCALNET>..42.124':51420
- '<LOCALNET>..42.126':51420
- '<LOCALNET>..42.128':51420
- '<LOCALNET>..42.132':51420
- '<LOCALNET>..42.134':51420
- '<LOCALNET>..42.136':51420
- '<LOCALNET>..42.138':51420
- '<LOCALNET>..42.112':51420
- '<LOCALNET>..42.140':51420
- '<LOCALNET>..42.142':51420
- '<LOCALNET>..42.144':51420
- '<LOCALNET>..42.146':51420
- '<LOCALNET>..42.148':51420
- '<LOCALNET>..42.152':51420
- '<LOCALNET>..42.154':51420
- '<LOCALNET>..42.158':51420
- '<LOCALNET>..42.160':51420
- '<LOCALNET>..42.162':51420
- '<LOCALNET>..42.164':51420
- '<LOCALNET>..42.166':51420
- '<LOCALNET>..42.168':51420
- '<LOCALNET>..42.170':51420
- '<LOCALNET>..42.174':51420
- '<LOCALNET>..42.178':51420
- '<LOCALNET>..42.180':51420
- '<LOCALNET>..42.182':51420
- '<LOCALNET>..42.57':51420
- '<LOCALNET>..42.186':51420
- '<LOCALNET>..42.59':51420
- '<LOCALNET>..42.61':51420
- '<LOCALNET>..42.188':51420
- '<LOCALNET>..42.63':51420
- '<LOCALNET>..42.192':51420
- '<LOCALNET>..42.65':51420
- '<LOCALNET>..42.67':51420
- '<LOCALNET>..42.118':51420
- '<LOCALNET>..42.172':51420
- '<LOCALNET>..42.69':51420
- '<LOCALNET>..42.176':51420
- '<LOCALNET>..42.71':51420
- '<LOCALNET>..42.73':51420
- '<LOCALNET>..42.75':51420
- '<LOCALNET>..42.77':51420
- '<LOCALNET>..42.79':51420
- '<LOCALNET>..42.81':51420
- '<LOCALNET>..42.83':51420
- '<LOCALNET>..42.85':51420
- '<LOCALNET>..42.87':51420
- '<LOCALNET>..42.89':51420
- '<LOCALNET>..42.97':51420
- '<LOCALNET>..42.91':51420
- '<LOCALNET>..42.95':51420
- '<LOCALNET>..42.99':51420
- '<LOCALNET>..42.101':51420
- '<LOCALNET>..42.156':51420
- '<LOCALNET>..42.184':51420
- '<LOCALNET>..42.190':51420
- '<LOCALNET>..42.130':51420
- '<LOCALNET>..42.150':51420
- '<LOCALNET>..42.196':51420
- '<LOCALNET>..42.31':51420
- '<LOCALNET>..42.93':51420
- '<LOCALNET>..42.198':51420
- '<LOCALNET>..42.194':51420
- '<LOCALNET>..42.103':51420
- '<LOCALNET>..42.105':51420
- '<LOCALNET>..42.111':51420
- '<LOCALNET>..42.107':51420
- '<LOCALNET>..42.113':51420
- '<LOCALNET>..42.117':51420
- '<LOCALNET>..42.115':51420
- '<LOCALNET>..42.119':51420
- '<LOCALNET>..42.125':51420
- '<LOCALNET>..42.127':51420
- '<LOCALNET>..42.129':51420
- '<LOCALNET>..42.131':51420
- '<LOCALNET>..42.133':51420
- '<LOCALNET>..42.121':51420
- '<LOCALNET>..42.135':51420
- '<LOCALNET>..42.139':51420
- '<LOCALNET>..42.141':51420
- '<LOCALNET>..42.145':51420
- '<LOCALNET>..42.149':51420
- '<LOCALNET>..42.151':51420
- '<LOCALNET>..42.153':51420
- '<LOCALNET>..42.137':51420
- '<LOCALNET>..42.157':51420
- '<LOCALNET>..42.155':51420
- '<LOCALNET>..42.159':51420
- '<LOCALNET>..42.161':51420
- '<LOCALNET>..42.165':51420
- '<LOCALNET>..42.171':51420
- '<LOCALNET>..42.173':51420
- '<LOCALNET>..42.175':51420
- '<LOCALNET>..42.181':51420
- '<LOCALNET>..42.179':51420
- '<LOCALNET>..42.185':51420
- '<LOCALNET>..42.183':51420
- '<LOCALNET>..42.193':51420
- '<LOCALNET>..42.195':51420
- '<LOCALNET>..42.189':51420
- '<LOCALNET>..42.197':51420
- '<LOCALNET>..42.191':51420
- '<LOCALNET>..42.199':51420
- '<LOCALNET>..42.123':51420
- '<LOCALNET>..42.143':51420
- '<LOCALNET>..42.167':51420
- '<LOCALNET>..42.169':51420
- '<LOCALNET>..42.163':51420
- '<LOCALNET>..42.177':51420
- '<LOCALNET>..42.187':51420
- '<LOCALNET>..42.109':51420
- '<LOCALNET>..42.147':51420
- '43.##9.192.68':46283
- '47.#8.35.46':36281
- '255.255.255.255':13512
- '<SYSTEM32>\bdeuisrv.exe'
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\FirewallControlPanel.dll,ShowNotificationDialog /configure /ETOnly 0 /OnProfiles 6 /OtherAllowed 0 /OtherBlocked 0 /OtherEdgeAllowed 0 /NewBlocked 4 "<SYSTEM32>\bdeuisrv.exe"
- '<SYSTEM32>\cmd.exe' /c del <Full path to file> >> NUL
- '<SYSTEM32>\cmd.exe' /c del <Full path to file> >> NUL' (with hidden window)