Technical Information
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'MicrosoftUpdate' = '%APPDATA%\Microsoft\svchost.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'MicrosoftUpdate' = '%APPDATA%\Microsoft\svchost.exe'
- [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe,%APPDATA%\Microsoft\svchost.exe'
- [HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe,%APPDATA%\Microsoft\svchost.exe'
- DNS ASK ze#######34.000webhostapp.com
- '%WINDIR%\syswow64\cmd.exe' /k ping 8.#.8.8 -n 5 & del <Full path to file> & exit
- '%WINDIR%\syswow64\ping.exe' 8.#.8.8 -n 5