Technical Information
- [HKCU\software\microsoft\windows\currentversion\run] 'IntelPowerAgent3' = 'rundll32.exe shell32.dll, ShellExec_RunDLL C:\PROGRA~3\D0BHJ2~1.EXE'
- %WINDIR%\syswow64\svchost.exe
- %WINDIR%\syswow64\cmd.exe
- iexplore.exe
- %WINDIR%\syswow64\svchost.exe
- %ALLUSERSPROFILE%\d0bhj2468j.exe
- %APPDATA%\faub222.tmp.bat
- DNS ASK vk.com
- '%WINDIR%\syswow64\svchost.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%APPDATA%\fauB222.tmp.bat" "<Full path to file>""
- '%WINDIR%\syswow64\svchost.exe' ' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ""%APPDATA%\fauB222.tmp.bat" "<Full path to file>""' (with hidden window)