Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'diskpart' = '"%APPDATA%\Microsoft\Windows\dllcache\diskpart.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'diskpart' = '"%APPDATA%\Microsoft\Windows\dllcache\diskpart.exe"'
- [<HKCU>\Software\Microsoft\Command Processor] 'AutoRun' = '"%APPDATA%\Microsoft\Windows\dllcache\diskpart.exe"'
- [<HKCU>\Control Panel\Desktop] 'SCRNSAVE.EXE' = '"%APPDATA%\Microsoft\Windows\dllcache\diskpart.exe"'
- %APPDATA%\microsoft\windows\start menu\programs\startup\diskpart.lnk
- [<HKLM>\System\CurrentControlSet\Services\EFS] 'Start' = '00000002'
- %WINDIR%\splwow64.exe
- iexplore.exe
- %APPDATA%\microsoft\windows\dllcache\diskpart.exe
- %APPDATA%\microsoft\windows\dllcache\jscript.dll
- %APPDATA%\microsoft\windows\dllcache\spfileq.dll
- %APPDATA%\microsoft\windows\dllcache\msnetobj.dll
- %APPDATA%\microsoft\windows\dllcache\ndproxystub.dll
- %APPDATA%\microsoft\windows\dllcache\rdpd3d.dll
- %APPDATA%\microsoft\windows\dllcache\scksp.dll
- %APPDATA%\microsoft\windows\dllcache\grpconv.exe
- %APPDATA%\microsoft\windows\dllcache\wabsyncprovider.dll
- %APPDATA%\microsoft\windows\dllcache\fdbth.dll
- %APPDATA%\microsoft\windows\dllcache\d2d1.dll
- %APPDATA%\microsoft\windows\dllcache\pegi-fi.rs
- %APPDATA%\microsoft\windows\dllcache\qedwipes.dll
- %APPDATA%\microsoft\windows\dllcache\tdh.dll
- %APPDATA%\microsoft\windows\dllcache\kbdtajik.dll
- %APPDATA%\microsoft\windows\dllcache\sbeio.dll
- %APPDATA%\microsoft\windows\dllcache\fdwnet.dll
- %APPDATA%\microsoft\windows\dllcache\cfgbkend.dll
- %APPDATA%\microsoft\windows\dllcache\ddaclsys.dll
- %APPDATA%\microsoft\windows\dllcache\wcneapauthproxy.dll
- %APPDATA%\microsoft\windows\dllcache\dbgeng.dll
- %APPDATA%\microsoft\windows\dllcache\basecsp.dll
- %APPDATA%\microsoft\windows\dllcache\cmdkey.exe
- %APPDATA%\microsoft\windows\dllcache\hbaapi.dll
- %APPDATA%\microsoft\windows\dllcache\wcncsvc.dll
- %APPDATA%\microsoft\windows\dllcache\locale.nls
- %APPDATA%\microsoft\windows\dllcache\adsldp.dll
- %APPDATA%\microsoft\windows\dllcache\xolehlp.dll
- %APPDATA%\microsoft\windows\dllcache\setupsnk.exe
- %APPDATA%\microsoft\windows\dllcache\playsndsrv.dll
- %APPDATA%\microsoft\windows\dllcache\fdwsd.dll
- %APPDATA%\microsoft\windows\dllcache\puiobj.dll
- %APPDATA%\microsoft\windows\dllcache\license.rtf
- %APPDATA%\microsoft\windows\dllcache\tapisysprep.dll
- %APPDATA%\microsoft\windows\dllcache\scesrv.dll
- %APPDATA%\microsoft\windows\dllcache\ubpm.dll
- %APPDATA%\microsoft\windows\dllcache\qmgrprxy.dll
- %APPDATA%\microsoft\windows\dllcache\xcopy.exe
- %APPDATA%\microsoft\windows\dllcache\nativehooks.dll
- %APPDATA%\microsoft\windows\dllcache\apilogen.dll
- %APPDATA%\microsoft\windows\dllcache\logagent.exe
- %APPDATA%\microsoft\windows\dllcache\mdminst.dll
- %APPDATA%\microsoft\windows\dllcache\gpapi.dll
- %APPDATA%\microsoft\windows\dllcache\ureg.dll
- %APPDATA%\microsoft\windows\dllcache\usbperf.dll
- %APPDATA%\microsoft\windows\dllcache\t2embed.dll
- %APPDATA%\microsoft\windows\dllcache\winsta.dll
- %APPDATA%\microsoft\windows\dllcache\shgina.dll
- %APPDATA%\microsoft\windows\dllcache\ac3acm.acm
- %APPDATA%\microsoft\windows\dllcache\netid.dll
- %APPDATA%\microsoft\windows\dllcache\f3ahvoas.dll
- %APPDATA%\microsoft\windows\dllcache\kbddv.dll
- %APPDATA%\microsoft\windows\dllcache\xwreg.dll
- %APPDATA%\microsoft\windows\dllcache\d3d8thk.dll
- %APPDATA%\microsoft\windows\dllcache\ir41_qc.dll
- %APPDATA%\microsoft\windows\dllcache\elslad.dll
- %APPDATA%\microsoft\windows\dllcache\taskschd.msc
- %APPDATA%\microsoft\windows\dllcache\rastapi.dll
- %APPDATA%\microsoft\windows\dllcache\d3d10warp.dll
- %APPDATA%\microsoft\windows\dllcache\d3dxof.dll
- %APPDATA%\microsoft\windows\dllcache\mfc100deu.dll
- %APPDATA%\microsoft\windows\dllcache\kbdarmw.dll
- %APPDATA%\microsoft\windows\dllcache\ulib.dll
- %APPDATA%\microsoft\windows\dllcache\helppaneproxy.dll
- %APPDATA%\microsoft\windows\dllcache\quick.ime
- %APPDATA%\microsoft\windows\dllcache\compobj.dll
- %APPDATA%\microsoft\windows\dllcache\vccorlib110d.dll
- %APPDATA%\microsoft\windows\dllcache\certreq.exe
- %APPDATA%\microsoft\windows\dllcache\kbd101b.dll
- %APPDATA%\microsoft\windows\dllcache\kbdsp.dll
- %APPDATA%\microsoft\windows\dllcache\capiprovider.dll
- %APPDATA%\microsoft\windows\dllcache\wcnapi.dll
- %APPDATA%\microsoft\windows\dllcache\taskeng.exe
- %APPDATA%\microsoft\windows\dllcache\samlib.dll
- %APPDATA%\microsoft\windows\dllcache\biocredprov.dll
- %APPDATA%\microsoft\windows\dllcache\ucrtbase.dll
- %APPDATA%\microsoft\windows\dllcache\samcli.dll
- %APPDATA%\microsoft\windows\dllcache\capisp.dll
- %APPDATA%\microsoft\windows\dllcache\pla.dll
- %APPDATA%\microsoft\windows\dllcache\ucrtbased.dll
- %APPDATA%\microsoft\windows\dllcache\dsdmo.dll
- %APPDATA%\microsoft\windows\dllcache\bopomofo.uce
- %APPDATA%\microsoft\windows\dllcache\mcewmdrmndbootstrap.dll
- %APPDATA%\microsoft\windows\dllcache\chkdsk.exe
- %APPDATA%\microsoft\windows\dllcache\eapp3hst.dll
- %APPDATA%\microsoft\windows\dllcache\dataclen.dll
- %APPDATA%\microsoft\windows\dllcache\occache.dll
- %APPDATA%\microsoft\windows\dllcache\kbd101a.dll
- %APPDATA%\microsoft\windows\dllcache\rasctrnm.h
- %APPDATA%\microsoft\windows\dllcache\mcbuilder.exe
- %APPDATA%\microsoft\windows\dllcache\oleprn.dll
- %APPDATA%\microsoft\windows\dllcache\takeown.exe
- %APPDATA%\microsoft\windows\dllcache\webcheck.dll
- %APPDATA%\microsoft\windows\dllcache\hlink.dll
- %APPDATA%\microsoft\windows\dllcache\web.rs
- %TEMP%\tmp12ce.tmp
- %APPDATA%\microsoft\windows\dllcache\rcx12fe.tmp
- %APPDATA%\microsoft\windows\dllcache\rcx134d.tmp
- %TEMP%\tmp138d.tmp
- C:\users\default\appdata\roaming\microsoft\windows\start menu\programs\startup\diskpart.lnk
- %APPDATA%\microsoft\windows\dllcache\kbdes.dll
- %APPDATA%\microsoft\windows\dllcache\ias.dll
- %APPDATA%\microsoft\windows\dllcache\esrb.rs
- %APPDATA%\microsoft\windows\dllcache\cero.rs
- %APPDATA%\microsoft\windows\dllcache\laprxy.dll
- %APPDATA%\microsoft\windows\dllcache\iasacct.dll
- %APPDATA%\microsoft\windows\dllcache\qagent.dll
- %APPDATA%\microsoft\windows\dllcache\icmui.dll
- %APPDATA%\microsoft\windows\dllcache\boot.sdi
- %APPDATA%\microsoft\windows\dllcache\d3d10core.dll
- %APPDATA%\microsoft\windows\dllcache\mode.com
- %APPDATA%\microsoft\windows\dllcache\ksproxy.ax
- %APPDATA%\microsoft\windows\dllcache\racengn.dll
- %APPDATA%\microsoft\windows\dllcache\rasautou.exe
- %APPDATA%\microsoft\windows\dllcache\l2gpstore.dll
- %APPDATA%\microsoft\windows\dllcache\oledlg.dll
- %APPDATA%\microsoft\windows\dllcache\grb.rs
- %APPDATA%\microsoft\windows\dllcache\pathping.exe
- %APPDATA%\microsoft\windows\dllcache\actioncenter.dll
- %APPDATA%\microsoft\windows\dllcache\l2sechc.dll
- %APPDATA%\microsoft\windows\dllcache\batmeter.dll
- %APPDATA%\microsoft\windows\dllcache\joy.cpl
- %APPDATA%\microsoft\windows\dllcache\catsrv.dll
- %APPDATA%\microsoft\windows\dllcache\magnify.exe
- %APPDATA%\microsoft\windows\dllcache\p2p.dll
- %APPDATA%\microsoft\windows\dllcache\ff_vfw.dll
- %APPDATA%\microsoft\windows\dllcache\iasdatastore.dll
- %APPDATA%\microsoft\windows\dllcache\odbctrac.dll
- %APPDATA%\microsoft\windows\dllcache\van.dll
- %APPDATA%\microsoft\windows\dllcache\onex.dll
- %APPDATA%\microsoft\windows\dllcache\aaclient.dll
- %APPDATA%\microsoft\windows\dllcache\cabinet.dll
- %APPDATA%\microsoft\windows\dllcache\efscore.dll
- %APPDATA%\microsoft\windows\dllcache\cacls.exe
- %APPDATA%\microsoft\windows\dllcache\els.dll
- %APPDATA%\microsoft\windows\dllcache\clb.dll
- %APPDATA%\microsoft\windows\dllcache\bdaplgin.ax
- %APPDATA%\microsoft\windows\dllcache\netprofm.dll
- %APPDATA%\microsoft\windows\dllcache\resampledmo.dll
- %APPDATA%\microsoft\windows\dllcache\napclcfg.msc
- %APPDATA%\microsoft\windows\dllcache\kbdtuq.dll
- %APPDATA%\microsoft\windows\dllcache\cca.dll
- %APPDATA%\microsoft\windows\dllcache\pku2u.dll
- %APPDATA%\microsoft\windows\dllcache\x264vfw.dll
- %APPDATA%\microsoft\windows\dllcache\gpedit.dll
- %APPDATA%\microsoft\windows\dllcache\mapisvc.inf
- %APPDATA%\microsoft\windows\dllcache\typelib.dll
- %APPDATA%\microsoft\windows\dllcache\wls0wndh.dll
- %APPDATA%\microsoft\windows\dllcache\adsldpc.dll
- %APPDATA%\microsoft\windows\dllcache\p2pcollab.dll
- %APPDATA%\microsoft\windows\dllcache\w32tm.exe
- %APPDATA%\microsoft\windows\dllcache\ideograf.uce
- %TEMP%\tmp12ce.tmp
- %TEMP%\tmp138d.tmp
- from %APPDATA%\microsoft\windows\dllcache\rcx12fe.tmp to %APPDATA%\microsoft\windows\dllcache\diskpart.exe
- from %APPDATA%\microsoft\windows\dllcache\rcx134d.tmp to %APPDATA%\microsoft\windows\dllcache\diskpart.exe
- '23.##9.166.139':666
- ClassName: 'TrayNotifyWnd' WindowName: ''
- ClassName: 'NotifyIconOverflowWindow' WindowName: ''
- '%APPDATA%\microsoft\windows\dllcache\diskpart.exe' "<Full path to file>"
- '%WINDIR%\syswow64\svchost.exe' -k netsvcs