Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '0dc235fc6220c7a63c91e5b6a297c21d' = '"%TEMP%\csrsss.exe" ..'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '0dc235fc6220c7a63c91e5b6a297c21d' = '"%TEMP%\csrsss.exe" ..'
- %APPDATA%\microsoft\windows\start menu\programs\startup\0dc235fc6220c7a63c91e5b6a297c21d.exe
- <Drive name for removable media>:\svchost.exe
- <Drive name for removable media>:\autorun.inf
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%TEMP%\csrsss.exe" "csrsss.exe" ENABLE
- '%WINDIR%\syswow64\taskkill.exe' /F /IM taskmgr.exe
- %APPDATA%\start.bat
- %APPDATA%\21.exe
- %APPDATA%\server.exe
- %TEMP%\csrsss.exe
- C:\svchost.exe
- C:\autorun.inf
- D:\svchost.exe
- D:\autorun.inf
- %APPDATA%\server.exe
- %TEMP%\csrsss.exe
- C:\svchost.exe
- C:\autorun.inf
- D:\svchost.exe
- D:\autorun.inf
- <Drive name for removable media>:\svchost.exe
- <Drive name for removable media>:\autorun.inf
- '46.##3.131.237':7777
- ClassName: 'EDIT' WindowName: ''
- ClassName: '' WindowName: ''
- '%APPDATA%\21.exe' -p0321654987 -d%APPDATA%
- '%APPDATA%\server.exe'
- '%TEMP%\csrsss.exe'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%TEMP%\csrsss.exe" "csrsss.exe" ENABLE' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /F /IM taskmgr.exe' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ""%APPDATA%\start.bat" "
- '%WINDIR%\syswow64\rundll32.exe' <SYSTEM32>\shell32.dll,OpenAs_RunDLL %APPDATA%\FortniteFPSBBOSTEYHEDN.cfg