Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'sys' = 'c:\ProgramData\rutserv.exe'
- %APPDATA%\Microsoft\up.exe
- %APPDATA%\Microsoft\Total.exe
- %APPDATA%\Microsoft\rutserv.exe
- %ALLUSERSPROFILE%\settings.dat
- %ALLUSERSPROFILE%\rutserv.exe
- %APPDATA%\Microsoft\7z.dll
- %TEMP%\nsa2.tmp\System.dll
- %APPDATA%\Microsoft\data.tmp
- %APPDATA%\Microsoft\settings.dat
- %APPDATA%\Microsoft\install.cmd
- %TEMP%\nsa2.tmp\System.dll
- '%APPDATA%\Microsoft\Total.exe' x -protectorScriptmail data.tmp -y
- '%APPDATA%\Microsoft\up.exe'
- '<SYSTEM32>\reg.exe' ADD "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /f /v "sys" /t REG_SZ /d "c:\ProgramData\rutserv.exe"
- '<SYSTEM32>\ping.exe' 127.0.0.1
- '<SYSTEM32>\cmd.exe' /c install.cmd