Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'UKO6cik1MH' = 'C:\UKO6cik1MHUKO6cik1MH\UKO6cik1MH.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'java' = '"%ALLUSERSPROFILE%\java\ulotmhvct.exe"'
- <SYSTEM32>\tasks\windows update check - 0x685c0874
- [<HKLM>\System\CurrentControlSet\Services\SSDPSRV] 'Start' = '00000002'
- %WINDIR%\syswow64\werfault.exe
- qwsowa.exe
- iexplore.exe process, wininet.dll module
- iexplore.exe process, dnsapi.dll module
- firefox.exe process, dnsapi.dll module
- firefox.exe process, nss3.dll module
- %WINDIR%\syswow64\schtasks.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '2500' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '2500' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '2500' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '2500' = '00000003'
- %TEMP%\sbgc1n\qwsowa.exe
- %TEMP%\sbgc1n\x
- %TEMP%\sbgc1n\a7yv.bmp
- C:\uko6cik1mhuko6cik1mh\x
- C:\uko6cik1mhuko6cik1mh\uko6cik1mh.exe
- %TEMP%\uko6cik1mh.txt
- %TEMP%\cmd.txt
- %TEMP%\csc.txt
- %ALLUSERSPROFILE%\java\ulotmhvct.exe
- from %WINDIR%\microsoft.net\framework\v2.0.50727\csc.exe to %ALLUSERSPROFILE%\java\safpdndnn.exe
- from %WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe to %ALLUSERSPROFILE%\java\hemxccape.exe
- from %TEMP%\sbgc1n\qwsowa.exe to %ALLUSERSPROFILE%\java\ulotmhvct.exe
- DNS ASK microsoft.com
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\sbgc1n\qwsowa.exe'
- '%TEMP%\sbgc1n\qwsowa.exe' _pers_
- '%WINDIR%\syswow64\cmd.exe' /c ping 127.0.0.1 && reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce" /v UKO6cik1MH /t REG_SZ /d "C:\UKO6cik1MHUKO6cik1MH\UKO6cik1MH.exe" /f' (with hidden window)
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /SC ONLOGON /TN "Windows Update Check - 0x685C0874" /TR "%ALLUSERSPROFILE%\java\safpdndnn.exe" /RL HIGHEST' (with hidden window)
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /SC ONLOGON /TN "Windows Update Check - 0x685C0874" /TR "%ALLUSERSPROFILE%\java\hemxccape.exe" /RL HIGHEST' (with hidden window)
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /SC ONLOGON /TN "Windows Update Check - 0x685C0874" /TR "%ALLUSERSPROFILE%\java\ulotmhvct.exe" /RL HIGHEST' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ping 127.0.0.1 && reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce" /v UKO6cik1MH /t REG_SZ /d "C:\UKO6cik1MHUKO6cik1MH\UKO6cik1MH.exe" /f
- '%WINDIR%\microsoft.net\framework\v2.0.50727\csc.exe'
- '%WINDIR%\syswow64\cmd.exe'
- '%WINDIR%\syswow64\ping.exe' 127.0.0.1
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /SC ONLOGON /TN "Windows Update Check - 0x685C0874" /TR "%ALLUSERSPROFILE%\java\safpdndnn.exe" /RL HIGHEST
- '%WINDIR%\syswow64\reg.exe' add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce" /v UKO6cik1MH /t REG_SZ /d "C:\UKO6cik1MHUKO6cik1MH\UKO6cik1MH.exe" /f
- '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe'
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /SC ONLOGON /TN "Windows Update Check - 0x685C0874" /TR "%ALLUSERSPROFILE%\java\hemxccape.exe" /RL HIGHEST
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /SC ONLOGON /TN "Windows Update Check - 0x685C0874" /TR "%ALLUSERSPROFILE%\java\ulotmhvct.exe" /RL HIGHEST