Technical Information
- [<HKLM>\SOFTWARE\Classes\MSProgramGroup\Shell\Open\Command] '' = '<SYSTEM32>\grpconv.exe %1'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'GrpConv' = 'grpconv -o'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ny02we' = '%APPDATA%\j8wxbv.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\MouseDriver] 'Start' = '00000002'
- %APPDATA%\j8wxbv.exe -dA8BB45AF5394EE317F8E93B431753C39188D7C0C98FAD91009658CFAFA2C3F57760AAEB3A4D8530D3C48913E97A9EAC26FAC50B893388CD0073E512D740B780AD69F6DC2C1C9E804BDFC52158378969C2017266A53E27E7E97256D05B743E660E7B02D3FAFB19C2C30F650078A497F2A67DA497AFEA540770725FBB578066AA80412D67FB1F3A07401304310824626A2C22F4242F9F8A3ECE47F510EAC7226CECCA990ED4D2B664ADD8A247E7FE14EE5EE85D96AE8CAB900FBF60B8488B07A991A65C6D449049F64B1C12CB6D746F6BEE7591752B1FCD15D58BB0090804607D00DB1202CA81A3B8AABAAD4451ED46122EADF466F790A7DC949F94AC24BB0AEC500EE862CB1396CD837D0D6EA29600EC875D5EED7A48B8F145B6C4109DC7191AB92DE22D5E8A3A29F023C2A550E10BF534593D963D85A16275B6880F76A1310629FD15E2412F68F30F9E8094421E07493565D0F4FFA7F659955FCDEB4688CCDB54326E1FC352B248F4A98ECB0F82E7017E54ADAB22E7D0C3F976C74608C0CA813DDF2952294F8916361178C016792328B706EC283DA30DBB6AE6B9D0ECB01C23A0981A418B5174819EB7EE39C835C7DB8B4C2914FA2EEE5086750F0455A287C6AA30D75475ED6F9DFD67B2999A22E502FAD454F346C1F7AD4CECE47F9AE44786DCA30B255935696494D62D76858B6ED6E98A845195DFA2BD8329EBA017C5797C4DAC544A7995A
- <SYSTEM32>\rundll32.exe setupapi,InstallHinfSection DefaultInstall 128 %APPDATA%\mdinstall.inf
- <SYSTEM32>\net1.exe stop "Windows Firewall/Internet Connection Sharing (ICS)"
- <SYSTEM32>\runonce.exe -r
- <SYSTEM32>\grpconv.exe -o
- <SYSTEM32>\cmd.exe /c "%APPDATA%\xp3xq07vv.bat"
- <SYSTEM32>\sc.exe config wscsvc start= DISABLED
- <SYSTEM32>\net.exe stop "Security Center"
- <SYSTEM32>\net.exe stop "Windows Firewall/Internet Connection Sharing (ICS)"
- <SYSTEM32>\net1.exe stop "Security Center"
- <SYSTEM32>\sc.exe config SharedAccess start= DISABLED
- %APPDATA%\mdinstall.inf
- %APPDATA%\xp3xq07vv.bat
- %APPDATA%\j8wxbv.exe
- %APPDATA%\MouseDriver.bat
- %APPDATA%\MouseDriver.bat
- %APPDATA%\mdinstall.inf
- 'w.#####ardiscover.com':888
- DNS ASK w.#####ardiscover.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''