Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'Tasksnngrs' = '%ALLUSERSPROFILE%\tasksnngr.exe'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'Taksnngrs' = '%ALLUSERSPROFILE%\taksnngr.exe'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] 'Taksnngr' = '%ALLUSERSPROFILE%\taksnngr.exe'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'Taksnmgrs' = '%APPDATA%\taksnmgr.exe'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] 'Taksnmgr' = '%APPDATA%\taksnmgr.exe'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] 'Tasksnngr' = '%ALLUSERSPROFILE%\tasksnngr.exe'
- [\REGISTRY\USER\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run] 'Tasksnngrs' = '%ALLUSERSPROFILE%\tasksnngr.exe'
- <SYSTEM32>\tasks\taskhandler\windows\taskmanager\settask\adobeupdater
- <SYSTEM32>\tasks\taskhandler\windows\taskmanager\settask\devicesmanager
- <SYSTEM32>\tasks\taskhandler\windows\taskmanager\settask\schedulemonitor
- <SYSTEM32>\tasks\taskhandler\windows\taskmanager\settask\securedusbmonitor
- <SYSTEM32>\tasks\taskhandler\windows\taskmanager\settask\tasksnngrs
- <SYSTEM32>\tasks\taskhandler\windows\taskmanager\settask\windowsupdatedscheck
- <SYSTEM32>\tasks\taskhandler\windows\taskmanager\settask\taksnngrs
- <SYSTEM32>\tasks\taskhandler\windows\taskmanager\settask\taksnngr
- <SYSTEM32>\tasks\taskhandler\windows\taskmanager\settask\taksnmgrs
- <SYSTEM32>\tasks\taskhandler\windows\taskmanager\settask\taksnmgr
- <SYSTEM32>\tasks\taskhandler\windows\taskmanager\settask\tasksnngr
- %TEMP%\<File name>.bmp
- C:\users\public\ambvcp.bat
- nul
- %ALLUSERSPROFILE%\taksnngr.exe
- C:\users\public\nlugik.bat
- %APPDATA%\taksnmgr.exe
- C:\users\public\kqdzsh.bat
- C:\users\public\hvnbcm.bat
- C:\users\public\kxhovn.bat
- C:\users\public\uvferh.bat
- C:\users\public\apcxui.bat
- C:\users\public\hcyhxk.bat
- C:\users\public\knsupl.bat
- C:\users\public\rzofbe.bat
- C:\users\public\axfdwg.bat
- C:\users\public\ehhihh.bat
- C:\users\public\hsbozi.bat
- C:\users\public\uruzod.bat
- C:\users\public\hzncug.bat
- C:\users\public\kjhhng.bat
- C:\users\public\xjalbb.bat
- C:\users\public\btcqtc.bat
- C:\users\public\eewved.bat
- C:\users\public\bafxoa.bat
- C:\users\public\rsannv.bat
- C:\users\public\eslqby.bat
- C:\users\public\ehwxew.bat
- C:\users\public\ikqcox.bat
- C:\users\public\vzumfq.bat
- C:\users\public\ignpmt.bat
- C:\users\public\ambvcp.bat
- C:\users\public\nlugik.bat
- C:\users\public\kqdzsh.bat
- C:\users\public\hvnbcm.bat
- C:\users\public\uvferh.bat
- C:\users\public\kxhovn.bat
- C:\users\public\hcyhxk.bat
- C:\users\public\apcxui.bat
- C:\users\public\rzofbe.bat
- C:\users\public\knsupl.bat
- C:\users\public\ehhihh.bat
- C:\users\public\axfdwg.bat
- C:\users\public\uruzod.bat
- C:\users\public\hsbozi.bat
- C:\users\public\hzncug.bat
- C:\users\public\kjhhng.bat
- C:\users\public\xjalbb.bat
- C:\users\public\eewved.bat
- C:\users\public\btcqtc.bat
- C:\users\public\bafxoa.bat
- C:\users\public\rsannv.bat
- C:\users\public\eslqby.bat
- C:\users\public\ikqcox.bat
- '255.255.255.255':19421
- '255.255.255.255':19419
- '255.255.255.255':19420
- '255.255.255.255':19422
- '255.255.255.255':19423
- '255.255.255.255':19424
- '255.255.255.255':19425
- '255.255.255.255':19426
- '255.255.255.255':19427
- '255.255.255.255':19428
- DNS ASK ni##.pk-gov.org
- ClassName: 'NarratorUIClass' WindowName: ''
- '%ALLUSERSPROFILE%\taksnngr.exe'
- '%APPDATA%\taksnmgr.exe'
- '%WINDIR%\syswow64\explorer.exe' %TEMP%\<File name>.bmp
- '%WINDIR%\syswow64\cmd.exe' /c C:\Users\Public\ambvcp.bat > nul
- '%WINDIR%\syswow64\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /v Tasksnngrs /t REG_SZ /d %ALLUSERSPROFILE%\tasksnngr.exe /f
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /SC Minute /MO 1 /TR C:\Adobe\adobeupdater.exe /TN TaskHandler\Windows\TaskManager\SetTask\AdobeUpdater /F
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /SC Minute /MO 1 /TR <SYSTEM32>\devicesmaneger.exe /TN TaskHandler\Windows\TaskManager\SetTask\DevicesManager /F
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /SC Minute /MO 1 /TR <SYSTEM32>\schedulemonitor.exe /TN TaskHandler\Windows\TaskManager\SetTask\ScheduleMonitor /F
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /SC Minute /MO 1 /TR <SYSTEM32>\securedusbmonitor.exe /TN TaskHandler\Windows\TaskManager\SetTask\SecuredUSBMonitor /F
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /SC Minute /MO 1 /TR %ALLUSERSPROFILE%\tasksnngr.exe /TN TaskHandler\Windows\TaskManager\SetTask\Tasksnngrs /F
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /SC Minute /MO 1 /TR <SYSTEM32>\winsupdatescheck.exe /TN TaskHandler\Windows\TaskManager\SetTask\WindowsUpdatedsCheck /F
- '%WINDIR%\syswow64\cmd.exe' /c C:\Users\Public\nlugik.bat > nul
- '%WINDIR%\syswow64\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /v Taksnngrs /t REG_SZ /d %ALLUSERSPROFILE%\taksnngr.exe /f
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /SC Minute /MO 1 /TR %ALLUSERSPROFILE%\taksnngr.exe /TN TaskHandler\Windows\TaskManager\SetTask\Taksnngrs /F
- '%WINDIR%\syswow64\reg.exe' add HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run /v Taksnngr /t REG_SZ /d %ALLUSERSPROFILE%\taksnngr.exe /f
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /RU SYSTEM /SC Minute /MO 1 /TR C:\Adobe\adobeupdater.exe /TN TaskHandler\Windows\TaskManager\SetTask\AdobeUpdater /RL Highest /F
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /RU SYSTEM /SC Minute /MO 1 /TR <SYSTEM32>\devicesmaneger.exe /TN TaskHandler\Windows\TaskManager\SetTask\DevicesManager /RL Highest /F
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /RU SYSTEM /SC Minute /MO 1 /TR <SYSTEM32>\schedulemonitor.exe /TN TaskHandler\Windows\TaskManager\SetTask\ScheduleMonitor /RL Highest /F
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /RU SYSTEM /SC Minute /MO 1 /TR <SYSTEM32>\securedusbmonitor.exe /TN TaskHandler\Windows\TaskManager\SetTask\SecuredUSBMonitor /RL Highest /F
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /RU SYSTEM /SC Minute /MO 1 /TR %ALLUSERSPROFILE%\taksnngr.exe /TN TaskHandler\Windows\TaskManager\SetTask\Taksnngr /RL Highest /F
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /RU SYSTEM /SC Minute /MO 1 /TR <SYSTEM32>\winsupdatescheck.exe /TN TaskHandler\Windows\TaskManager\SetTask\WindowsUpdatedsCheck /RL Highest /F
- '%WINDIR%\syswow64\cmd.exe' /c C:\Users\Public\kqdzsh.bat > nul
- '<SYSTEM32>\svchost.exe' -k appmodel -p -s camsvc
- '%WINDIR%\syswow64\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /v Taksnmgrs /t REG_SZ /d %APPDATA%\taksnmgr.exe /f
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /SC Minute /MO 1 /TR %APPDATA%\taksnmgr.exe /TN TaskHandler\Windows\TaskManager\SetTask\Taksnmgrs /F
- '%WINDIR%\syswow64\reg.exe' add HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run /v Taksnmgr /t REG_SZ /d %APPDATA%\taksnmgr.exe /f
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /RU SYSTEM /SC Minute /MO 1 /TR %APPDATA%\taksnmgr.exe /TN TaskHandler\Windows\TaskManager\SetTask\Taksnmgr /RL Highest /F
- '%WINDIR%\syswow64\cmd.exe' /c C:\Users\Public\hvnbcm.bat > nul
- '%WINDIR%\syswow64\cmd.exe' /c C:\Users\Public\kxhovn.bat > nul
- '%WINDIR%\syswow64\cmd.exe' /c C:\Users\Public\uvferh.bat > nul
- '%WINDIR%\syswow64\reg.exe' add HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run /v Tasksnngr /t REG_SZ /d %ALLUSERSPROFILE%\tasksnngr.exe /f
- '%WINDIR%\syswow64\cmd.exe' /c C:\Users\Public\apcxui.bat > nul
- '%WINDIR%\syswow64\cmd.exe' /c C:\Users\Public\hcyhxk.bat > nul
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /RU SYSTEM /SC Minute /MO 1 /TR %ALLUSERSPROFILE%\tasksnngr.exe /TN TaskHandler\Windows\TaskManager\SetTask\Tasksnngr /RL Highest /F
- '%WINDIR%\syswow64\cmd.exe' /c C:\Users\Public\knsupl.bat > nul
- '%WINDIR%\syswow64\cmd.exe' /c C:\Users\Public\rzofbe.bat > nul
- '%WINDIR%\syswow64\cmd.exe' /c C:\Users\Public\axfdwg.bat > nul
- '%WINDIR%\syswow64\cmd.exe' /c C:\Users\Public\ehhihh.bat > nul
- '%WINDIR%\syswow64\cmd.exe' /c C:\Users\Public\hsbozi.bat > nul
- '%WINDIR%\syswow64\cmd.exe' /c C:\Users\Public\uruzod.bat > nul
- '%WINDIR%\syswow64\cmd.exe' /c C:\Users\Public\hzncug.bat > nul
- '%WINDIR%\syswow64\cmd.exe' /c C:\Users\Public\kjhhng.bat > nul
- '%WINDIR%\syswow64\cmd.exe' /c C:\Users\Public\xjalbb.bat > nul
- '%WINDIR%\syswow64\cmd.exe' /c C:\Users\Public\btcqtc.bat > nul
- '%WINDIR%\syswow64\cmd.exe' /c C:\Users\Public\eewved.bat > nul
- '%WINDIR%\syswow64\cmd.exe' /c C:\Users\Public\bafxoa.bat > nul
- '%WINDIR%\syswow64\cmd.exe' /c C:\Users\Public\rsannv.bat > nul
- '%WINDIR%\syswow64\cmd.exe' /c C:\Users\Public\eslqby.bat > nul
- '%WINDIR%\syswow64\cmd.exe' /c C:\Users\Public\ehwxew.bat > nul
- '%WINDIR%\syswow64\cmd.exe' /c C:\Users\Public\ikqcox.bat > nul
- '%WINDIR%\syswow64\cmd.exe' /c C:\Users\Public\vzumfq.bat > nul
- '%WINDIR%\syswow64\cmd.exe' /c C:\Users\Public\ignpmt.bat > nul
- '%ALLUSERSPROFILE%\taksnngr.exe' ' (with hidden window)
- '%APPDATA%\taksnmgr.exe' ' (with hidden window)