Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'BWUnhlpr' = '<SYSTEM32>\d3dxsjob.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '<SYSTEM32>\d3dxsjob.exe' = '00000000'
- %WINDIR%\explorer.exe
- iexplore.exe
- iexplore.exe process, urlmon.dll module
- iexplore.exe process, wininet.dll module
- firefox.exe process, advapi32.dll module
- firefox.exe process, wininet.dll module
- firefox.exe process, nss3.dll module
- iexplore.exe process, advapi32.dll module
- firefox.exe process, urlmon.dll module
- %WINDIR%\explorer.exe
- %HOMEPATH%\desktop\ituneshelpunavailable.htm
- %HOMEPATH%\desktop\garden.htm
- %HOMEPATH%\desktop\advice_process.htm
- %HOMEPATH%\desktop\64bit_notes.htm
- %HOMEPATH%\desktop\aoc_saq_d_v3_merchant.docx
- <SYSTEM32>\d3dxsjob.exe
- %APPDATA%\microsoft\{772e1c12-6ab9-c199-2c9b-3e8520ff5289}\cookie.ie\user@mozilla[2].txt
- %APPDATA%\microsoft\{772e1c12-6ab9-c199-2c9b-3e8520ff5289}\cookie.ie\user@msn[1].txt
- %APPDATA%\microsoft\{772e1c12-6ab9-c199-2c9b-3e8520ff5289}\cookie.ie\user@msn[2].txt
- %APPDATA%\microsoft\{772e1c12-6ab9-c199-2c9b-3e8520ff5289}\cookie.ie\user@onlinestores.metaservices.microsoft[1].txt
- %APPDATA%\microsoft\{772e1c12-6ab9-c199-2c9b-3e8520ff5289}\cookie.ie\user@scorecardresearch[2].txt
- %APPDATA%\microsoft\{772e1c12-6ab9-c199-2c9b-3e8520ff5289}\cookie.ie\user@scorecardresearch[3].txt
- %APPDATA%\microsoft\{772e1c12-6ab9-c199-2c9b-3e8520ff5289}\cookie.ie\user@sportiv[2].txt
- %APPDATA%\microsoft\{772e1c12-6ab9-c199-2c9b-3e8520ff5289}\cookie.ie\user@www.bing[1].txt
- %APPDATA%\microsoft\{772e1c12-6ab9-c199-2c9b-3e8520ff5289}\cookie.ie\user@www.msn[2].txt
- %APPDATA%\microsoft\{772e1c12-6ab9-c199-2c9b-3e8520ff5289}\cookie.ie\user@www.msn[3].txt
- %APPDATA%\microsoft\{772e1c12-6ab9-c199-2c9b-3e8520ff5289}\cookie.ie\user@yandex[1].txt
- %APPDATA%\microsoft\{772e1c12-6ab9-c199-2c9b-3e8520ff5289}\cookie.ie\user@yandex[2].txt
- %TEMP%\553d.tmp
- %TEMP%\615e.bat
- %TEMP%\5452.tmp1
- %APPDATA%\microsoft\{772e1c12-6ab9-c199-2c9b-3e8520ff5289}\cookie.ie\user@demdex[2].txt
- %TEMP%\5452.tmp
- %APPDATA%\microsoft\{772e1c12-6ab9-c199-2c9b-3e8520ff5289}\cookie.ie\user@c.msn[2].txt
- %APPDATA%\microsoft\{772e1c12-6ab9-c199-2c9b-3e8520ff5289}\cookie.ie\user@c.bing[2].txt
- %TEMP%\e342.tmp
- %APPDATA%\microsoft\{157a4251-7084-0f4d-2219-a4b3765d1897}
- %TEMP%\50ca.tmp
- %APPDATA%\microsoft\{772e1c12-6ab9-c199-2c9b-3e8520ff5289}\cookie.ff\gn7ryp3k.default\cookies.sqlite
- %APPDATA%\microsoft\{772e1c12-6ab9-c199-2c9b-3e8520ff5289}\sols\#sharedobjects\gr8by44n\kiks.yandex.ru\fuid01.sol
- %APPDATA%\microsoft\{772e1c12-6ab9-c199-2c9b-3e8520ff5289}\sols\macromedia.com\support\flashplayer\sys\settings.sol
- %APPDATA%\microsoft\{772e1c12-6ab9-c199-2c9b-3e8520ff5289}\sols\macromedia.com\support\flashplayer\sys\#kiks.yandex.ru\settings.sol
- %APPDATA%\microsoft\{772e1c12-6ab9-c199-2c9b-3e8520ff5289}\sols\macromedia.com\support\flashplayer\sys\#yastatic.net\settings.sol
- %APPDATA%\microsoft\{772e1c12-6ab9-c199-2c9b-3e8520ff5289}\cookie.ie\user@246059135.log.optimizely[1].txt
- %APPDATA%\microsoft\{772e1c12-6ab9-c199-2c9b-3e8520ff5289}\cookie.ie\user@adnxs[1].txt
- %APPDATA%\microsoft\{772e1c12-6ab9-c199-2c9b-3e8520ff5289}\cookie.ie\user@adobe[1].txt
- %APPDATA%\microsoft\{772e1c12-6ab9-c199-2c9b-3e8520ff5289}\cookie.ie\user@adobe[3].txt
- %APPDATA%\microsoft\{772e1c12-6ab9-c199-2c9b-3e8520ff5289}\cookie.ie\user@bing[1].txt
- %APPDATA%\microsoft\{772e1c12-6ab9-c199-2c9b-3e8520ff5289}\cookie.ie\user@bing[2].txt
- %APPDATA%\microsoft\{772e1c12-6ab9-c199-2c9b-3e8520ff5289}\cookie.ie\user@c.bing[1].txt
- %APPDATA%\microsoft\{772e1c12-6ab9-c199-2c9b-3e8520ff5289}\cookie.ie\user@c.msn[1].txt
- %TEMP%\ee9e.tmp
- %TEMP%\e342.tmp
- %TEMP%\e342.tmp
- %TEMP%\50ca.tmp
- %TEMP%\553d.tmp
- %TEMP%\5452.tmp1
- %TEMP%\5452.tmp
- %TEMP%\553d.tmp
- '85.##.118.113':80
- ClassName: 'SystemTray_Main' WindowName: ''
- ClassName: 'Progman' WindowName: ''
- ClassName: 'Proxy Desktop' WindowName: ''
- ClassName: 'Media Center Tray Applet' WindowName: ''
- ClassName: '' WindowName: 'View Available Networks'
- ClassName: 'BluetoothNotificationAreaIconWindowClass' WindowName: 'BluetoothNotificationAreaIconWindowClass'
- ClassName: 'BluetoothNotificationAreaIconWindowClass' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\615E.bat" "<Full path to file>""' (with hidden window)
- '%WINDIR%\explorer.exe'
- '<SYSTEM32>\cmd.exe' /C "systeminfo.exe > %TEMP%\5452.tmp1"
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\615E.bat" "<Full path to file>""
- '%WINDIR%\syswow64\attrib.exe' -r -s -h "<Full path to file>"
- '<SYSTEM32>\systeminfo.exe'
- '<SYSTEM32>\cmd.exe' /C "echo -------- >> %TEMP%\5452.tmp1"
- '<SYSTEM32>\cmd.exe' /C "tasklist.exe /SVC >> %TEMP%\5452.tmp1"
- '<SYSTEM32>\tasklist.exe' /SVC
- '<SYSTEM32>\cmd.exe' /C "driverquery.exe >> %TEMP%\5452.tmp1"
- '<SYSTEM32>\driverquery.exe'
- '<SYSTEM32>\cmd.exe' /C "reg.exe query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall" /s >> %TEMP%\5452.tmp1"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall" /s
- '<SYSTEM32>\cmd.exe' /U /C "type %TEMP%\5452.tmp1 > %TEMP%\5452.tmp & del %TEMP%\5452.tmp1"