Technical Information
- [HKLM\Software\Classes\.com] '' = 'txtfile-'
- [HKLM\Software\Classes\.bat] '' = 'txtfile-'
- [HKLM\Software\Classes\.cmd] '' = 'txtfile-'
- [HKLM\Software\Classes\.exe] '' = 'txtfile -'
- '<SYSTEM32>\taskkill.exe' /f /im explorer.exe
- '<SYSTEM32>\taskkill.exe' /f /im HipsTray.exe /t
- '<SYSTEM32>\taskkill.exe' /f /im 360Tray.exe /t
- '<SYSTEM32>\taskkill.exe' /f /im ZhuDongFangYu.exe /t
- %WINDIR%\explorer.exe
- %TEMP%\a931.tmp\a932.tmp\a933.bat
- from <SYSTEM32>\catroot2\edbtmp.log to <SYSTEM32>\catroot2\edb.log
- ClassName: '' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\A931.tmp\A932.tmp\A933.bat <Full path to file>"
- '<SYSTEM32>\timeout.exe' 3
- '<SYSTEM32>\cmd.exe' /c "del /f /s /q <SYSTEM32>\config\*.*"
- '<SYSTEM32>\cmd.exe' /c "del /f /s /q <SYSTEM32>\*.*"