Technical Information
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'MarvelHost' = '┢偁䑐呁╁浜瑨灯㈳楢硥≥'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'MarvelHost' = '┢偁䑐呁╁浜瑨灯㈳楢硥≥'
- '%WINDIR%\syswow64\taskkill.exe' /f /im MSExchange*
- '%WINDIR%\syswow64\taskkill.exe' /f /im Microsoft.Exchange.*
- '%WINDIR%\syswow64\taskkill.exe' /f /im sqlserver.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im sqlwriter.exe
- %APPDATA%\mhtop32bit.exe
- ClassName: '' WindowName: ''
- '%WINDIR%\syswow64\sc.exe' stop wscsvc' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' stop WinDefend' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' stop wuauserv' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' stop BITS' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' stop ERSvc' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' stop WerSvc' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c bcdedit /set {default} recoveryenabled No' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c bcdedit /set {default} bootstatuspolicy ignoreallfailures' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin delete shadows /all /quiet' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c wmic shadowcopy delete' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c wbadmin delete catalog -quiet' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im MSExchange*' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im Microsoft.Exchange.*' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im sqlserver.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im sqlwriter.exe' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c copy "<Full path to file>" "%APPDATA%\mhtop32bit.exe"' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' stop wscsvc
- '%WINDIR%\syswow64\sc.exe' stop WinDefend
- '%WINDIR%\syswow64\sc.exe' stop wuauserv
- '%WINDIR%\syswow64\sc.exe' stop BITS
- '%WINDIR%\syswow64\sc.exe' stop ERSvc
- '%WINDIR%\syswow64\sc.exe' stop WerSvc
- '%WINDIR%\syswow64\cmd.exe' /c bcdedit /set {default} recoveryenabled No
- '%WINDIR%\syswow64\cmd.exe' /c bcdedit /set {default} bootstatuspolicy ignoreallfailures
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin delete shadows /all /quiet
- '%WINDIR%\syswow64\cmd.exe' /c wmic shadowcopy delete
- '%WINDIR%\syswow64\cmd.exe' /c wbadmin delete catalog -quiet
- '%WINDIR%\syswow64\cmd.exe' /c copy "<Full path to file>" "%APPDATA%\mhtop32bit.exe"
- '<SYSTEM32>\vssvc.exe'