Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '1' = 'wscript.exe //B "%APPDATA%\1.vbs"'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '1' = 'wscript.exe //B "%APPDATA%\1.vbs"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '5e9db1eafc1af2ffec1c8c2c746ba57d' = '"%APPDATA%\winloage.exe" ..'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '5e9db1eafc1af2ffec1c8c2c746ba57d' = '"%APPDATA%\winloage.exe" ..'
- %HOMEPATH%\Start Menu\Programs\Startup\1.vbs
- %HOMEPATH%\Start Menu\Programs\Startup\5e9db1eafc1af2ffec1c8c2c746ba57d.exe
- %HOMEPATH%\Start Menu\Programs\Startup\Worm Server.exe
- <Drive name for removable media>:\1.vbs
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%APPDATA%\winloage.exe' = '%APPDATA%\winloage.exe:*:Enabled:winloage.exe'
- '%APPDATA%\2.exe'
- '%APPDATA%\winloage.exe'
- '%TEMP%\Worm Server.exe'
- '%TEMP%\MW3 Trainer.exe'
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%APPDATA%\winloage.exe" "winloage.exe" ENABLE
- '<SYSTEM32>\wscript.exe' "%APPDATA%\1.vbs"
- %APPDATA%\1.vbs
- %APPDATA%\2.exe
- %APPDATA%\winloage.exe
- %TEMP%\MW3 Trainer.exe
- %TEMP%\aut1.tmp
- %TEMP%\Worm Server.exe
- %TEMP%\aut2.tmp
- <Drive name for removable media>:\1.vbs
- %TEMP%\aut2.tmp
- %TEMP%\aut1.tmp
- 'ec####7.dynu.net':81
- 'localhost':1041
- 'ec####7.dynu.net':1177
- DNS ASK ec####7.dynu.net
- ClassName: 'Indicator' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'