Technical Information
- Windows Task Manager (Taskmgr)
- C:\chainsavessessiondllnet\9exzyhdojz7uij.bat
- C:\chainsavessessiondllnet\portserver.exe
- C:\chainsavessessiondllnet\9xsjq4iw.vbe
- ClassName: 'EDIT' WindowName: ''
- '%WINDIR%\syswow64\wscript.exe' "C:\chainsavessessiondllnet\9XSJQ4IW.vbe"
- 'C:\chainsavessessiondllnet\portserver.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""C:\chainsavessessiondllnet\9EXZyHDoJz7uij.bat" "
- '%WINDIR%\syswow64\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 1 /f
- '%WINDIR%\syswow64\cmd.exe' /c ""C:\chainsavessessiondllnet\9EXZyHDoJz7uij.bat" "' (with hidden window)