Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'a7623f0eab1d7c8818b03754c176b24f' = '"%TEMP%\dwm..exe" ..'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'a7623f0eab1d7c8818b03754c176b24f' = '"%TEMP%\dwm..exe" ..'
- %APPDATA%\microsoft\windows\start menu\programs\startup\a7623f0eab1d7c8818b03754c176b24f.exe
- <Drive name for removable media>:\svchost.exe
- <Drive name for removable media>:\autorun.inf
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%TEMP%\dwm..exe" "dwm..exe" ENABLE
- %TEMP%\dwm..exe
- C:\svchost.exe
- C:\autorun.inf
- D:\svchost.exe
- D:\autorun.inf
- <Full path to file>
- %TEMP%\dwm..exe
- C:\svchost.exe
- C:\autorun.inf
- D:\svchost.exe
- D:\autorun.inf
- <Drive name for removable media>:\svchost.exe
- <Drive name for removable media>:\autorun.inf
- 'sl####ng99.ddns.net':5552
- DNS ASK sl####ng99.ddns.net
- '%TEMP%\dwm..exe'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%TEMP%\dwm..exe" "dwm..exe" ENABLE' (with hidden window)