Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'wmi32' = '"%PROGRAMDATA%\Application Data\wmimgmt.exe"'
- <Drive name for removable media>:\recycler\desktop.ini
- <Drive name for removable media>:\~thumbs.tmp
- <Drive name for removable media>:\recycler\wmimgmt.com
- wmimgmt.exe
- %TEMP%\temp.vih
- %PROGRAMDATA%\application data\wmimgmt.exe
- <LS_APPDATA>\Microsoft\windows\<INETFILES>\drivers.p
- <LS_APPDATA>\Microsoft\windows\<INETFILES>\ghi.bat
- <LS_APPDATA>\Microsoft\windows\<INETFILES>\info.txt
- <Drive name for removable media>:\recycler\desktop.ini
- <Drive name for removable media>:\autorun.inf
- %TEMP%\temp.vih
- %TEMP%\temp.vih
- DNS ASK windowsupdate.microsoft.com
- ClassName: 'MS_WINHELP' WindowName: ''
- '%PROGRAMDATA%\application data\wmimgmt.exe'
- '%PROGRAMDATA%\application data\wmimgmt.exe' ' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /v:on /c "<LS_APPDATA>\Microsoft\Windows\<INETFILES>\ghi.bat"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /v:on /c "<LS_APPDATA>\Microsoft\Windows\<INETFILES>\ghi.bat"
- '%WINDIR%\syswow64\findstr.exe' /s "YM.CGP_" "%HOMEPATH%"\..\*.txt