Technical Information
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'LAN Subsystem' = '%ProgramFiles(x86)%\LAN Subsystem\lanss.exe'
- <SYSTEM32>\tasks\lan subsystem
- <SYSTEM32>\tasks\lan subsystem task
- %TEMP%\nanoinvoice.exe
- %TEMP%\autbad6.tmp
- %TEMP%\zuicsjw
- %TEMP%\autbb44.tmp
- %TEMP%\ylzztw.jpg
- %APPDATA%\0cb67e2f-dc95-45ca-8fb8-69bde8e3f814\run.dat
- %ProgramFiles(x86)%\lan subsystem\lanss.exe
- %TEMP%\tmpd47d.tmp
- %APPDATA%\0cb67e2f-dc95-45ca-8fb8-69bde8e3f814\task.dat
- %TEMP%\tmpd7b9.tmp
- %TEMP%\autbad6.tmp
- %TEMP%\zuicsjw
- %TEMP%\autbb44.tmp
- %TEMP%\tmpd47d.tmp
- %TEMP%\tmpd7b9.tmp
- 'localhost':1212
- DNS ASK no####ip.ddns.net
- DNS ASK no####ip1.ddns.net
- '%TEMP%\nanoinvoice.exe'
- '%WINDIR%\syswow64\schtasks.exe' /create /f /tn "LAN Subsystem" /xml "%TEMP%\tmpD47D.tmp"
- '%WINDIR%\syswow64\schtasks.exe' /create /f /tn "LAN Subsystem Task" /xml "%TEMP%\tmpD7B9.tmp"