Technical Information
- <SYSTEM32>\tasks\firefoxf
- <SYSTEM32>\tasks\firefox
- <SYSTEM32>\tasks\lsassl
- <SYSTEM32>\tasks\fast1njectf
- <SYSTEM32>\tasks\lsass
- <SYSTEM32>\tasks\lsm
- <SYSTEM32>\tasks\fast1nject
- <SYSTEM32>\tasks\lsml
- <SYSTEM32>\tasks\sppsvc
- <SYSTEM32>\tasks\wininit
- <SYSTEM32>\tasks\wininitw
- <SYSTEM32>\tasks\smsss
- <SYSTEM32>\tasks\sppsvcs
- <SYSTEM32>\tasks\winlogonw
- <SYSTEM32>\tasks\smss
- <SYSTEM32>\tasks\reviewref_protectedr
- <SYSTEM32>\tasks\wudfhostw
- <SYSTEM32>\tasks\wudfhost
- <SYSTEM32>\tasks\winlogon
- <SYSTEM32>\tasks\reviewref_protected
- ClassName: 'OLLYDBG', WindowName: ''
- %TEMP%\fast1nject.exe
- %TEMP%\1.sfx.exe
- %TEMP%\1.exe
- %TEMP%\1.bat
- %TEMP%\reviewref_protected.exe
- C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\firefox.exe
- C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\0fc223bdacedc3
- %WINDIR%\appcompat\programs\lsass.exe
- %WINDIR%\appcompat\programs\6203df4a6bafc7
- <Current directory>\fast1nject.exe
- <Current directory>\6b742e12dd0856
- %ProgramFiles%\windows defender\en-us\lsm.exe
- %ProgramFiles%\windows defender\en-us\101b941d020240
- C:\kms\sppsvc.exe
- C:\kms\0a1fd5f707cd16
- C:\kms\wininit.exe
- C:\kms\56085415360792
- C:\kms\smss.exe
- C:\kms\69ddcba757bf72
- C:\recovery\4d53d3aa-5835-11ef-baad-8f07b80b2fb5\wininit.exe
- C:\recovery\4d53d3aa-5835-11ef-baad-8f07b80b2fb5\56085415360792
- %HOMEPATH%\documents\my music\winlogon.exe
- %HOMEPATH%\documents\my music\cc11b995f2a76d
- C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\smss.exe
- C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\69ddcba757bf72
- C:\recovery\4d53d3aa-5835-11ef-baad-8f07b80b2fb5\lsass.exe
- C:\recovery\4d53d3aa-5835-11ef-baad-8f07b80b2fb5\6203df4a6bafc7
- %ProgramFiles(x86)%\microsoft visual studio 8\vsta\bin\1033\firefox.exe
- %ProgramFiles(x86)%\microsoft visual studio 8\vsta\bin\1033\0fc223bdacedc3
- C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\reviewref_protected.exe
- C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\aa065569cf55df
- C:\kms\wudfhost.exe
- C:\kms\480b7989c529f6
- %TEMP%\shxvvi0ztz
- %TEMP%\ffseemubvh.bat
- nul
- %TEMP%\shxvvi0ztz
- 'ra#.####ubusercontent.com':443
- 'ra#.####ubusercontent.com':443
- DNS ASK ra#.####ubusercontent.com
- DNS ASK cb###00.tw1.ru
- 'localhost':123
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\fast1nject.exe'
- '%TEMP%\1.sfx.exe'
- '%TEMP%\1.exe' -plsadfjhiodsajuf[dasef[0uj9rqwe9uj234h[32ho9i8243ioh8
- '%TEMP%\reviewref_protected.exe'
- 'C:\kms\wudfhost.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\1.bat" "
- '<SYSTEM32>\schtasks.exe' /create /tn "firefoxf" /sc MINUTE /mo 5 /tr "'C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\firefox.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefox" /sc ONLOGON /tr "'C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefoxf" /sc MINUTE /mo 8 /tr "'C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "lsassl" /sc MINUTE /mo 8 /tr "'%WINDIR%\AppCompat\Programs\lsass.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "lsass" /sc ONLOGON /tr "'%WINDIR%\AppCompat\Programs\lsass.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "lsassl" /sc MINUTE /mo 8 /tr "'%WINDIR%\AppCompat\Programs\lsass.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "fast1njectf" /sc MINUTE /mo 14 /tr "'<Current directory>\fast1nject.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "fast1nject" /sc ONLOGON /tr "'<Current directory>\fast1nject.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "fast1njectf" /sc MINUTE /mo 7 /tr "'<Current directory>\fast1nject.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "lsml" /sc MINUTE /mo 12 /tr "'%ProgramFiles%\Windows Defender\en-US\lsm.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "lsm" /sc ONLOGON /tr "'%ProgramFiles%\Windows Defender\en-US\lsm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "lsml" /sc MINUTE /mo 8 /tr "'%ProgramFiles%\Windows Defender\en-US\lsm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "sppsvcs" /sc MINUTE /mo 10 /tr "'C:\kms\sppsvc.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "sppsvc" /sc ONLOGON /tr "'C:\kms\sppsvc.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "sppsvcs" /sc MINUTE /mo 11 /tr "'C:\kms\sppsvc.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "wininitw" /sc MINUTE /mo 10 /tr "'C:\kms\wininit.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "wininit" /sc ONLOGON /tr "'C:\kms\wininit.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "wininitw" /sc MINUTE /mo 12 /tr "'C:\kms\wininit.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "smsss" /sc MINUTE /mo 10 /tr "'C:\kms\smss.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "smss" /sc ONLOGON /tr "'C:\kms\smss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "smsss" /sc MINUTE /mo 10 /tr "'C:\kms\smss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "wininitw" /sc MINUTE /mo 9 /tr "'C:\Recovery\4d53d3aa-5835-11ef-baad-8f07b80b2fb5\wininit.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "wininit" /sc ONLOGON /tr "'C:\Recovery\4d53d3aa-5835-11ef-baad-8f07b80b2fb5\wininit.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "wininitw" /sc MINUTE /mo 14 /tr "'C:\Recovery\4d53d3aa-5835-11ef-baad-8f07b80b2fb5\wininit.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "winlogonw" /sc MINUTE /mo 13 /tr "'%HOMEPATH%\Documents\My Music\winlogon.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "winlogon" /sc ONLOGON /tr "'%HOMEPATH%\Documents\My Music\winlogon.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "winlogonw" /sc MINUTE /mo 8 /tr "'%HOMEPATH%\Documents\My Music\winlogon.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "smsss" /sc MINUTE /mo 13 /tr "'C:\MSOCache\All Users\{90140000-0011-0000-1000-0000000FF1CE}-C\smss.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "smss" /sc ONLOGON /tr "'C:\MSOCache\All Users\{90140000-0011-0000-1000-0000000FF1CE}-C\smss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "smsss" /sc MINUTE /mo 13 /tr "'C:\MSOCache\All Users\{90140000-0011-0000-1000-0000000FF1CE}-C\smss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "lsassl" /sc MINUTE /mo 9 /tr "'C:\Recovery\4d53d3aa-5835-11ef-baad-8f07b80b2fb5\lsass.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "lsass" /sc ONLOGON /tr "'C:\Recovery\4d53d3aa-5835-11ef-baad-8f07b80b2fb5\lsass.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "lsassl" /sc MINUTE /mo 9 /tr "'C:\Recovery\4d53d3aa-5835-11ef-baad-8f07b80b2fb5\lsass.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefoxf" /sc MINUTE /mo 14 /tr "'%ProgramFiles(x86)%\Microsoft Visual Studio 8\VSTA\Bin\1033\firefox.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefox" /sc ONLOGON /tr "'%ProgramFiles(x86)%\Microsoft Visual Studio 8\VSTA\Bin\1033\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefoxf" /sc MINUTE /mo 13 /tr "'%ProgramFiles(x86)%\Microsoft Visual Studio 8\VSTA\Bin\1033\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "reviewref_protectedr" /sc MINUTE /mo 12 /tr "'C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\reviewref_protected.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "reviewref_protected" /sc ONLOGON /tr "'C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\reviewref_protected.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "reviewref_protectedr" /sc MINUTE /mo 12 /tr "'C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\reviewref_protected.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "WUDFHostW" /sc MINUTE /mo 14 /tr "'C:\kms\WUDFHost.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "WUDFHost" /sc ONLOGON /tr "'C:\kms\WUDFHost.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "WUDFHostW" /sc MINUTE /mo 11 /tr "'C:\kms\WUDFHost.exe'" /rl HIGHEST /f
- '%WINDIR%\syswow64\cmd.exe' /C "%TEMP%\FfSEeMUBvh.bat"
- '%WINDIR%\syswow64\w32tm.exe' /stripchart /computer:localhost /period:5 /dataonly /samples:2
- '<SYSTEM32>\w32tm.exe' /stripchart /computer:localhost /period:5 /dataonly /samples:2
- '%WINDIR%\syswow64\cmd.exe' /C "%TEMP%\FfSEeMUBvh.bat"' (with hidden window)