Technical Information
- <SYSTEM32>\tasks\smsss
- <SYSTEM32>\tasks\iexplorei
- <SYSTEM32>\tasks\winlogon
- <SYSTEM32>\tasks\explorer
- <SYSTEM32>\tasks\wudfhost
- <SYSTEM32>\tasks\explorere
- <SYSTEM32>\tasks\wudfhostw
- <SYSTEM32>\tasks\firefoxf
- <SYSTEM32>\tasks\dwm
- <SYSTEM32>\tasks\wininit
- <SYSTEM32>\tasks\dwmd
- <SYSTEM32>\tasks\wininitw
- <SYSTEM32>\tasks\firefox
- <SYSTEM32>\tasks\audiodg
- <SYSTEM32>\tasks\audiodga
- <SYSTEM32>\tasks\wmiprvse
- <SYSTEM32>\tasks\wmiprvsew
- <SYSTEM32>\tasks\smss
- <SYSTEM32>\tasks\iexplore
- <SYSTEM32>\tasks\winlogonw
- C:\kms\smss.exe
- %ProgramFiles%\internet explorer\en-us\7a0fd90576e088
- %ProgramFiles%\internet explorer\en-us\iexplore.exe
- %ProgramFiles%\internet explorer\en-us\9db6e019d4f04e
- C:\recovery\4cc8e8a4-51d2-11ee-b826-9a90d4dcffb5\dwm.exe
- C:\recovery\4cc8e8a4-51d2-11ee-b826-9a90d4dcffb5\6cb0b6c459d5d3
- %ALLUSERSPROFILE%\adobe\arm\s\480b7989c529f6
- %ProgramFiles%\internet explorer\en-us\explorer.exe
- %ProgramFiles%\internet explorer\explorer.exe
- C:\recovery\4cc8e8a4-51d2-11ee-b826-9a90d4dcffb5\0fc223bdacedc3
- C:\users\default\firefox.exe
- C:\users\default\0fc223bdacedc3
- %ProgramFiles%\microsoft analysis services\as oledb\firefox.exe
- %ProgramFiles%\microsoft analysis services\as oledb\0fc223bdacedc3
- %ProgramFiles%\internet explorer\7a0fd90576e088
- C:\recovery\4cc8e8a4-51d2-11ee-b826-9a90d4dcffb5\firefox.exe
- %ALLUSERSPROFILE%\adobe\arm\s\wudfhost.exe
- <Current directory>\0fc223bdacedc3
- <Current directory>\firefox.exe
- %WINDIR%\offline web pages\wmiprvse.exe
- %WINDIR%\offline web pages\24dbde2999530e
- <Current directory>\audiodg.exe
- <Current directory>\42af1c969fbb7b
- C:\recovery\4cc8e8a4-51d2-11ee-b826-9a90d4dcffb5\wininit.exe
- C:\recovery\4cc8e8a4-51d2-11ee-b826-9a90d4dcffb5\56085415360792
- C:\kms\69ddcba757bf72
- %ProgramFiles%\windows mail\firefox.exe
- C:\recovery\4cc8e8a4-51d2-11ee-b826-9a90d4dcffb5\audiodg.exe
- C:\recovery\4cc8e8a4-51d2-11ee-b826-9a90d4dcffb5\42af1c969fbb7b
- C:\users\public\libraries\smss.exe
- C:\users\public\libraries\69ddcba757bf72
- %ProgramFiles%\windows mail\en-us\dwm.exe
- %ProgramFiles%\windows mail\en-us\6cb0b6c459d5d3
- %ProgramFiles%\windows mail\0fc223bdacedc3
- <Current directory>\winlogon.exe
- <Current directory>\cc11b995f2a76d
- 'cm###26.tw1.ru':80
- http://cm###26.tw1.ru/_Defaultwindows.php?W0#####################################################################################################################################################...
- http://cm###26.tw1.ru/_Defaultwindows.php?Fs#####################################################################################################################################################...
- DNS ASK cm###26.tw1.ru
- '<Current directory>\winlogon.exe'
- '<Current directory>\winlogon.exe' ' (with hidden window)
- '<SYSTEM32>\schtasks.exe' /create /tn "smsss" /sc MINUTE /mo 5 /tr "'C:\kms\smss.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "WUDFHostW" /sc MINUTE /mo 6 /tr "'%ALLUSERSPROFILE%\Adobe\ARM\S\WUDFHost.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "explorere" /sc MINUTE /mo 9 /tr "'%ProgramFiles%\Internet Explorer\en-US\explorer.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "explorer" /sc ONLOGON /tr "'%ProgramFiles%\Internet Explorer\en-US\explorer.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "explorere" /sc MINUTE /mo 13 /tr "'%ProgramFiles%\Internet Explorer\en-US\explorer.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "iexplorei" /sc MINUTE /mo 8 /tr "'%ProgramFiles%\Internet Explorer\en-US\iexplore.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "iexplore" /sc ONLOGON /tr "'%ProgramFiles%\Internet Explorer\en-US\iexplore.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "iexplorei" /sc MINUTE /mo 11 /tr "'%ProgramFiles%\Internet Explorer\en-US\iexplore.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "dwmd" /sc MINUTE /mo 11 /tr "'C:\Recovery\4cc8e8a4-51d2-11ee-b826-9a90d4dcffb5\dwm.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "dwm" /sc ONLOGON /tr "'C:\Recovery\4cc8e8a4-51d2-11ee-b826-9a90d4dcffb5\dwm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "dwmd" /sc MINUTE /mo 5 /tr "'C:\Recovery\4cc8e8a4-51d2-11ee-b826-9a90d4dcffb5\dwm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "WUDFHostW" /sc MINUTE /mo 6 /tr "'%ALLUSERSPROFILE%\Adobe\ARM\S\WUDFHost.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "WUDFHost" /sc ONLOGON /tr "'%ALLUSERSPROFILE%\Adobe\ARM\S\WUDFHost.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "explorere" /sc MINUTE /mo 14 /tr "'%ProgramFiles%\Internet Explorer\explorer.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefoxf" /sc MINUTE /mo 8 /tr "'C:\Recovery\4cc8e8a4-51d2-11ee-b826-9a90d4dcffb5\firefox.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefox" /sc ONLOGON /tr "'C:\Recovery\4cc8e8a4-51d2-11ee-b826-9a90d4dcffb5\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefoxf" /sc MINUTE /mo 10 /tr "'C:\Recovery\4cc8e8a4-51d2-11ee-b826-9a90d4dcffb5\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefoxf" /sc MINUTE /mo 5 /tr "'C:\Users\Default\firefox.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefox" /sc ONLOGON /tr "'C:\Users\Default\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefoxf" /sc MINUTE /mo 11 /tr "'C:\Users\Default\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefoxf" /sc MINUTE /mo 5 /tr "'%ProgramFiles%\Microsoft Analysis Services\AS OLEDB\firefox.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefox" /sc ONLOGON /tr "'%ProgramFiles%\Microsoft Analysis Services\AS OLEDB\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefoxf" /sc MINUTE /mo 9 /tr "'%ProgramFiles%\Microsoft Analysis Services\AS OLEDB\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "winlogonw" /sc MINUTE /mo 8 /tr "'<Current directory>\winlogon.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "explorer" /sc ONLOGON /tr "'%ProgramFiles%\Internet Explorer\explorer.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "explorere" /sc MINUTE /mo 8 /tr "'%ProgramFiles%\Internet Explorer\explorer.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefoxf" /sc MINUTE /mo 7 /tr "'<Current directory>\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefox" /sc ONLOGON /tr "'<Current directory>\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefoxf" /sc MINUTE /mo 5 /tr "'<Current directory>\firefox.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "smsss" /sc MINUTE /mo 10 /tr "'C:\kms\smss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "smsss" /sc MINUTE /mo 13 /tr "'C:\kms\smss.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "smsss" /sc MINUTE /mo 11 /tr "'C:\kms\smss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "WmiPrvSEW" /sc MINUTE /mo 14 /tr "'%WINDIR%\Offline Web Pages\WmiPrvSE.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "WmiPrvSE" /sc ONLOGON /tr "'%WINDIR%\Offline Web Pages\WmiPrvSE.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "WmiPrvSEW" /sc MINUTE /mo 11 /tr "'%WINDIR%\Offline Web Pages\WmiPrvSE.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "audiodga" /sc MINUTE /mo 8 /tr "'<Current directory>\audiodg.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "audiodg" /sc ONLOGON /tr "'<Current directory>\audiodg.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "audiodga" /sc MINUTE /mo 10 /tr "'<Current directory>\audiodg.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "wininitw" /sc MINUTE /mo 5 /tr "'C:\Recovery\4cc8e8a4-51d2-11ee-b826-9a90d4dcffb5\wininit.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "wininit" /sc ONLOGON /tr "'C:\Recovery\4cc8e8a4-51d2-11ee-b826-9a90d4dcffb5\wininit.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "smss" /sc ONLOGON /tr "'C:\kms\smss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "wininitw" /sc MINUTE /mo 10 /tr "'C:\Recovery\4cc8e8a4-51d2-11ee-b826-9a90d4dcffb5\wininit.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefox" /sc ONLOGON /tr "'%ProgramFiles%\Windows Mail\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefoxf" /sc MINUTE /mo 7 /tr "'%ProgramFiles%\Windows Mail\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "audiodga" /sc MINUTE /mo 14 /tr "'C:\Recovery\4cc8e8a4-51d2-11ee-b826-9a90d4dcffb5\audiodg.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "audiodg" /sc ONLOGON /tr "'C:\Recovery\4cc8e8a4-51d2-11ee-b826-9a90d4dcffb5\audiodg.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "audiodga" /sc MINUTE /mo 7 /tr "'C:\Recovery\4cc8e8a4-51d2-11ee-b826-9a90d4dcffb5\audiodg.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "smsss" /sc MINUTE /mo 8 /tr "'C:\Users\Public\Libraries\smss.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "smss" /sc ONLOGON /tr "'C:\Users\Public\Libraries\smss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "smsss" /sc MINUTE /mo 6 /tr "'C:\Users\Public\Libraries\smss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "dwmd" /sc MINUTE /mo 12 /tr "'%ProgramFiles%\Windows Mail\en-US\dwm.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "dwm" /sc ONLOGON /tr "'%ProgramFiles%\Windows Mail\en-US\dwm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "dwmd" /sc MINUTE /mo 7 /tr "'%ProgramFiles%\Windows Mail\en-US\dwm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefoxf" /sc MINUTE /mo 9 /tr "'%ProgramFiles%\Windows Mail\firefox.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "winlogon" /sc ONLOGON /tr "'<Current directory>\winlogon.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "winlogonw" /sc MINUTE /mo 6 /tr "'<Current directory>\winlogon.exe'" /rl HIGHEST /f