Technical Information
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '<File name>.exe' = '<Full path to file>'
- %WINDIR%\explorer.exe
- nul
- from <Full path to file> to <Full path to file>.deleted
- DNS ASK ap#.msn.com
- ClassName: 'Progman' WindowName: ''
- ClassName: 'Proxy Desktop' WindowName: ''
- ClassName: 'ApplicationFrameWindow' WindowName: ''
- ClassName: 'SystemTray_Main' WindowName: ''
- ClassName: 'BluetoothNotificationAreaIconWindowClass' WindowName: 'BluetoothNotificationAreaIconWindowClass'
- ClassName: 'BluetoothNotificationAreaIconWindowClass' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c "TIMEOUT /T 3 /NOBREAK >NUL & DEL \"<Full path to file>.deleted\" & EXIT"
- '<SYSTEM32>\timeout.exe' /T 3 /NOBREAK
- '%WINDIR%\explorer.exe'
- '%WINDIR%\systemapps\microsoft.windows.search_cw5n1h2txyewy\searchapp.exe' -ServerName:CortanaUI.AppX8z9r6jm96hw4bsbneegw0kyxx296wr9t.mca
- '<SYSTEM32>\svchost.exe' -k appmodel -p -s camsvc
- '<SYSTEM32>\werfault.exe' -u -p 3316 -s 5336' (with hidden window)