Technical Information
- [<HKCU>\software\microsoft\windows\currentversion\run] 'LwUockUk.exe' = '%HOMEPATH%\pWIAkIsM\LwUockUk.exe'
- [<HKLM>\software\Wow6432Node\microsoft\windows\currentversion\run] 'AksMksYI.exe' = '%ALLUSERSPROFILE%\muoUgQMg\AksMksYI.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,%ALLUSERSPROFILE%\muoUgQMg\AksMksYI.exe,'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = 'userinit.exe,%ALLUSERSPROFILE%\muoUgQMg\AksMksYI.exe,'
- [<HKLM>\System\CurrentControlSet\Services\QQsIoITC] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\QQsIoITC] 'ImagePath' = '%ALLUSERSPROFILE%\QcEUMQEw\LUAYoIYw.exe'
- 'QQsIoITC' %ALLUSERSPROFILE%\QcEUMQEw\LUAYoIYw.exe
- hidden files
- file extensions
- User Account Control (UAC)
- %HOMEPATH%\pwiakism\lwuockuk
- %ALLUSERSPROFILE%\muougqmg\aksmksyi
- %HOMEPATH%\pwiakism\lwuockuk.exe
- %ALLUSERSPROFILE%\muougqmg\aksmksyi.exe
- %ALLUSERSPROFILE%\qceumqew\luayoiyw.exe
- %WINDIR%\syswow64\config\systemprofile\pwiakism\lwuockuk
- %TEMP%\eaisicme.bat
- %TEMP%\setup.exe
- %ALLUSERSPROFILE%\cayo.txt
- <Current directory>\qiss.ico
- <Current directory>\gqwc.exe
- <Current directory>\uwmo.exe
- <Current directory>\fkws.exe
- <Current directory>\vees.exe
- %TEMP%\eaisicme.bat
- <Current directory>\gqwc.exe
- <Current directory>\uwmo.exe
- <Current directory>\fkws.exe
- <Current directory>\vees.exe
- http://google.com/
- DNS ASK bl##k.io
- DNS ASK google.com
- ClassName: '' WindowName: 'AksMksYI.exe'
- ClassName: '' WindowName: 'Microsoft Windows'
- ClassName: '' WindowName: 'LwUockUk.exe'
- '%HOMEPATH%\pwiakism\lwuockuk.exe'
- '%ALLUSERSPROFILE%\muougqmg\aksmksyi.exe'
- '%ALLUSERSPROFILE%\qceumqew\luayoiyw.exe'
- '%TEMP%\setup.exe'
- '%WINDIR%\syswow64\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\setup.exe
- '%WINDIR%\syswow64\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1
- '%WINDIR%\syswow64\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2
- '%WINDIR%\syswow64\reg.exe' add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f