Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'firefox' = '"<Current directory>\firefox.exe"'
- [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] 'firefox' = '"<Current directory>\firefox.exe"'
- [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe, "<Current directory>\firefox.exe"'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] '<File name>' = '"C:\MSOCache\All Users\{90160000-0011-0000-0000-0000000FF1CE}-C\<File name>.exe"'
- [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] '<File name>' = '"C:\MSOCache\All Users\{90160000-0011-0000-0000-0000000FF1CE}-C\<File name>.exe"'
- [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe, "<Current directory>\firefox.exe", "C:\MSOCache\All Users\{90160000-0011-0000-0000-0000000FF1CE}-C\<File na...
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'SearchApp' = '"%ProgramFiles(x86)%\Mozilla Firefox\plugins\SearchApp.exe"'
- [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] 'SearchApp' = '"%ProgramFiles(x86)%\Mozilla Firefox\plugins\SearchApp.exe"'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'fontdrvhost' = '"C:\Recovery\WindowsRE\fontdrvhost.exe"'
- [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] 'fontdrvhost' = '"C:\Recovery\WindowsRE\fontdrvhost.exe"'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'iexplore' = '"C:\MSOCache\All Users\{90160000-001A-0409-0000-0000000FF1CE}-C\iexplore.exe"'
- [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] 'iexplore' = '"C:\MSOCache\All Users\{90160000-001A-0409-0000-0000000FF1CE}-C\iexplore.exe"'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] '<File name>' = '"<Full path to file>"'
- [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] '<File name>' = '"<Full path to file>"'
- <SYSTEM32>\tasks\firefoxf
- <SYSTEM32>\tasks\firefox
- <SYSTEM32>\tasks\<File name>y
- <SYSTEM32>\tasks\<File name>
- <SYSTEM32>\tasks\searchapps
- <SYSTEM32>\tasks\searchapp
- <SYSTEM32>\tasks\fontdrvhostf
- <SYSTEM32>\tasks\fontdrvhost
- <SYSTEM32>\tasks\iexplorei
- <SYSTEM32>\tasks\iexplore
- <Current directory>\d9b82090f8f7e7
- C:\msocache\all users\{90160000-001a-0409-0000-0000000ff1ce}-c\iexplore.exe
- C:\msocache\all users\{90160000-001a-0409-0000-0000000ff1ce}-c\9db6e019d4f04e
- C:\recovery\windowsre\fontdrvhost.exe
- C:\recovery\windowsre\5b884080fd4f94
- %ProgramFiles(x86)%\mozilla firefox\plugins\searchapp.exe
- %ProgramFiles(x86)%\mozilla firefox\plugins\38384e6a620884
- C:\msocache\all users\{90160000-0011-0000-0000-0000000ff1ce}-c\<File name>.exe
- C:\msocache\all users\{90160000-0011-0000-0000-0000000ff1ce}-c\d9b82090f8f7e7
- <Current directory>\firefox.exe
- <Current directory>\0fc223bdacedc3
- %TEMP%\content\3292-3264-<File name>.exe-15-41-27-408.dump
- %TEMP%\content\3292-3264-<File name>.exe-15-41-28-169.dump
- %TEMP%\content\3292-3264-<File name>.exe-15-41-28-334.dump
- %TEMP%\content\3292-3264-<File name>.exe-15-41-28-691.dump
- %TEMP%\content\3292-3264-<File name>.exe-15-41-28-892.dump
- %TEMP%\content\3292-3264-<File name>.exe-15-41-29-156.dump
- %TEMP%\content\3292-3264-<File name>.exe-15-41-29-768.dump
- %TEMP%\content\3292-3264-<File name>.exe-15-41-30-335.dump
- %TEMP%\content\3292-3264-<File name>.exe-15-41-31-048.dump
- %TEMP%\content\3292-3264-<File name>.exe-15-41-31-636.dump
- %TEMP%\content\3292-3264-<File name>.exe-15-41-31-890.dump
- %TEMP%\content\3292-3264-<File name>.exe-15-41-32-109.dump
- %TEMP%\content\3292-3264-<File name>.exe-15-41-32-440.dump
- %TEMP%\content\3292-3264-<File name>.exe-15-41-32-649.dump
- %TEMP%\content\3292-3264-<File name>.exe-15-41-32-952.dump
- %TEMP%\content\3292-3264-<File name>.exe-15-41-33-192.dump
- %TEMP%\content\3292-3264-<File name>.exe-15-41-33-499.dump
- %TEMP%\content\3292-3264-<File name>.exe-15-41-33-669.dump
- %TEMP%\hp4fhjd0er
- %TEMP%\mzyweyqy3k.bat
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\<File name>.exe.log
- nul
- %HOMEPATH%\desktop\rrcfhldr.log
- %HOMEPATH%\desktop\meyokshu.log
- %HOMEPATH%\desktop\uswjqwmf.log
- %HOMEPATH%\desktop\kjdthugy.log
- %TEMP%\cigu97g4i9
- %TEMP%\ecvqfnjznv.bat
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\firefox.exe.log
- %HOMEPATH%\desktop\jigdawur.log
- %HOMEPATH%\desktop\vuaillwl.log
- %HOMEPATH%\desktop\vbrwdwbk.log
- %HOMEPATH%\desktop\buuvgcgy.log
- %TEMP%\dyqmcdgrqq
- %TEMP%\z8efjwb7jj.bat
- %HOMEPATH%\desktop\kcrujhzz.log
- %HOMEPATH%\desktop\tmysynwy.log
- %HOMEPATH%\desktop\rqdxvpwb.log
- %HOMEPATH%\desktop\zebrbtbm.log
- %TEMP%\hpxz2dqeyf
- %TEMP%\mgpvijiv5s.bat
- %HOMEPATH%\desktop\dycadtsa.log
- %HOMEPATH%\desktop\gpxjjygs.log
- %HOMEPATH%\desktop\vlixvxao.log
- %HOMEPATH%\desktop\kxehllfg.log
- %TEMP%\uhqvoa9sse
- %TEMP%\wozxytzlgh.bat
- %HOMEPATH%\desktop\pfzdjrvj.log
- %HOMEPATH%\desktop\yitffuci.log
- %HOMEPATH%\desktop\fqgzlprt.log
- %TEMP%\hp4fhjd0er
- %TEMP%\cigu97g4i9
- %TEMP%\dyqmcdgrqq
- %TEMP%\hpxz2dqeyf
- %TEMP%\uhqvoa9sse
- DNS ASK 70#####m.nyashnyash.ru
- 'localhost':123
- '<Current directory>\firefox.exe'
- '<SYSTEM32>\schtasks.exe' /create /tn "firefoxf" /sc MINUTE /mo 7 /tr "'<Current directory>\firefox.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefox" /sc ONLOGON /tr "'<Current directory>\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefoxf" /sc MINUTE /mo 8 /tr "'<Current directory>\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "<File name>y" /sc MINUTE /mo 12 /tr "'C:\MSOCache\All Users\{90160000-0011-0000-0000-0000000FF1CE}-C\<File name>.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "<File name>" /sc ONLOGON /tr "'C:\MSOCache\All Users\{90160000-0011-0000-0000-0000000FF1CE}-C\<File name>.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "<File name>y" /sc MINUTE /mo 14 /tr "'C:\MSOCache\All Users\{90160000-0011-0000-0000-0000000FF1CE}-C\<File name>.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "SearchAppS" /sc MINUTE /mo 6 /tr "'%ProgramFiles(x86)%\Mozilla Firefox\plugins\SearchApp.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "SearchApp" /sc ONLOGON /tr "'%ProgramFiles(x86)%\Mozilla Firefox\plugins\SearchApp.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "SearchAppS" /sc MINUTE /mo 12 /tr "'%ProgramFiles(x86)%\Mozilla Firefox\plugins\SearchApp.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "fontdrvhostf" /sc MINUTE /mo 7 /tr "'C:\Recovery\WindowsRE\fontdrvhost.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "fontdrvhost" /sc ONLOGON /tr "'C:\Recovery\WindowsRE\fontdrvhost.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "fontdrvhostf" /sc MINUTE /mo 7 /tr "'C:\Recovery\WindowsRE\fontdrvhost.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "iexplorei" /sc MINUTE /mo 13 /tr "'C:\MSOCache\All Users\{90160000-001A-0409-0000-0000000FF1CE}-C\iexplore.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "iexplore" /sc ONLOGON /tr "'C:\MSOCache\All Users\{90160000-001A-0409-0000-0000000FF1CE}-C\iexplore.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "iexplorei" /sc MINUTE /mo 7 /tr "'C:\MSOCache\All Users\{90160000-001A-0409-0000-0000000FF1CE}-C\iexplore.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "<File name>y" /sc MINUTE /mo 13 /tr "'<Full path to file>'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "<File name>" /sc ONLOGON /tr "'<Full path to file>'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "<File name>y" /sc MINUTE /mo 13 /tr "'<Full path to file>'" /rl HIGHEST /f
- '<SYSTEM32>\cmd.exe' /C "%TEMP%\MzYWeYQY3k.bat"
- '<SYSTEM32>\chcp.com' 65001
- '<SYSTEM32>\ping.exe' -n 10 localhost
- '<SYSTEM32>\cmd.exe' /C "%TEMP%\ECvQfnJznV.bat"
- '<SYSTEM32>\cmd.exe' /C "%TEMP%\Z8EFjwB7Jj.bat"
- '<SYSTEM32>\w32tm.exe' /stripchart /computer:localhost /period:5 /dataonly /samples:2
- '<SYSTEM32>\cmd.exe' /C "%TEMP%\mGpvIJIv5S.bat"
- '<SYSTEM32>\cmd.exe' /C "%TEMP%\WOZXYTZLgh.bat"
- '<SYSTEM32>\cmd.exe' /C "%TEMP%\p8DYq14q3H.bat"
- '<SYSTEM32>\cmd.exe' /C "%TEMP%\MzYWeYQY3k.bat"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C "%TEMP%\ECvQfnJznV.bat"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C "%TEMP%\Z8EFjwB7Jj.bat"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C "%TEMP%\mGpvIJIv5S.bat"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C "%TEMP%\WOZXYTZLgh.bat"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C "%TEMP%\p8DYq14q3H.bat"' (with hidden window)