Technical Information
- [HKLM\SYSTEM\CurrentControlSet\Services\gjltejrr] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\gjltejrr] 'ImagePath' = '%APPDATA%\Microsoft\Yjzartij\yjzarti.exe /D'
- 'gjltejrr' %APPDATA%\Microsoft\Yjzartij\yjzarti.exe /D
- %WINDIR%\syswow64\explorer.exe
- %WINDIR%\inf\display.pnf
- %APPDATA%\microsoft\yjzartij\yjzart.dll
- %APPDATA%\microsoft\yjzartij\yjzarti.exe
- '%APPDATA%\microsoft\yjzartij\yjzarti.exe'
- '%APPDATA%\microsoft\yjzartij\yjzarti.exe' /C
- '%WINDIR%\syswow64\cmd.exe' /c ping.exe -n 6 127.0.0.1 & type "<SYSTEM32>\autoconv.exe" > "<Full path to file>"
- '%WINDIR%\syswow64\ping.exe' -n 6 127.0.0.1
- '%WINDIR%\syswow64\explorer.exe'
- '<Full path to file>' /C' (with hidden window)
- '%APPDATA%\microsoft\yjzartij\yjzarti.exe' ' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ping.exe -n 6 127.0.0.1 & type "<SYSTEM32>\autoconv.exe" > "<Full path to file>"' (with hidden window)
- '%APPDATA%\microsoft\yjzartij\yjzarti.exe' /C' (with hidden window)