Technical Information
- [<HKLM>\SOFTWARE\Classes\MSProgramGroup\Shell\Open\Command] '' = '<SYSTEM32>\grpconv.exe %1'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'GrpConv' = 'grpconv -o'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'r5ie7t' = '%APPDATA%\0y2r.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\MouseDriver] 'Start' = '00000002'
- %APPDATA%\0y2r.exe -dD7C4D933C00775AA85747A5D2064D1D443D60F7F33515F9681EDDAAC86508BE3D1ADB2AFE39F055BEE9AF85776485C74FE3DCD252E85CE92142D82FE66195E2CF9B050FFC5CD28C42C6D4A0D6398F2F827108FC32D9C0303E456C4AC8A7E38BEA0F7C2D03E2054E4DF198BDC8F4C98CDB00D83B0A7FC93A43210DD933A443CFE574153FA692B3EEAE8D91A49E5219317CA2715155756541B7FE4481700DED038EF8A90ED9CFADBF7693E92C88D1368C3E58EF24135175BE28C81C54AA49C987B7A05485A733E609BC2B2D248EF7EDD95B20C07427A37FB7759BA4FDF2FE97AAD47FB868AC57741F09495F564B67CF6B5231682ABA0D3CB7F289823ABEB109BF0E8069933AC243581C0275A66C980F73169C9CFF65E71A03B7A4DBFF760CD5F652F630BFC80CB2F1268569DE2534D678BF5239B21AF2D8DAE1023E09758216C062B6BAC15DC0066CDED379AB9BB750BD77754D382CB76E9CFEB0E8223DBC3A6172FBC87CA979E4D86EE1570F7AB1AE690E00EA5C32CA649234C10E293338333EECBDFEB3CCBA19A624E217BF20D0E3E81627E7D5289B781FAB37A7EF5E803786DCF5C63D7D04742092DA557DB08DD99416ECD0892DDFEA643E2DF13BEC49F1A0D4E20BCB940397A51ED5DE3660684BAF9B41233B05F280EB5
- <SYSTEM32>\rundll32.exe setupapi,InstallHinfSection DefaultInstall 128 %APPDATA%\mdinstall.inf
- <SYSTEM32>\net1.exe stop "Windows Firewall/Internet Connection Sharing (ICS)"
- <SYSTEM32>\runonce.exe -r
- <SYSTEM32>\grpconv.exe -o
- <SYSTEM32>\cmd.exe /c "%APPDATA%\f7le8hpd.bat"
- <SYSTEM32>\sc.exe config wscsvc start= DISABLED
- <SYSTEM32>\net.exe stop "Security Center"
- <SYSTEM32>\net.exe stop "Windows Firewall/Internet Connection Sharing (ICS)"
- <SYSTEM32>\net1.exe stop "Security Center"
- <SYSTEM32>\sc.exe config SharedAccess start= DISABLED
- %APPDATA%\mdinstall.inf
- %APPDATA%\f7le8hpd.bat
- %APPDATA%\0y2r.exe
- %APPDATA%\MouseDriver.bat
- %APPDATA%\MouseDriver.bat
- %APPDATA%\mdinstall.inf
- 'w.#####ardiscover.com':888
- DNS ASK w.#####ardiscover.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''