Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'svchos' = '<SYSTEM32>\Dwm.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'svchos' = 'C:\users\Public\xmAhg.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'svchos' = 'C:\users\Public\HVvUgYV.exe'
- <SYSTEM32>\dwm.exe
- '<SYSTEM32>\net.exe' stop "audioendpointbuilder" /y
- '<SYSTEM32>\net.exe' stop "samss" /y
- <SYSTEM32>\taskhost.exe
- C:\users\public\xmahg.exe
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\documents\my music\sam...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\officesoftwa...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\search\data\...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\windows\devi...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\windows\powe...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\windows defe...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\windows nt\m...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\user account...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\42d5bec7...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{01db25f...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{0f12c81...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{2af972c...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{33d1fd9...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft help\ms.netf...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{35459b2...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{51adbf1...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{615bc16...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{6c95b50...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{74d0e5d...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{a219961...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{b55f720...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{ce085a7...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{dde2682...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{e46eca4...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{f0080ca...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{f65db02...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\start menu\programs\ac...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\start menu\programs\ad...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\start menu\programs\k-...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\documents\my pictures\...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\start menu\programs\mi...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\assistance\c...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\event viewer...
- C:\users\public\hvvugyv.exe
- %PROGRAMDATA%\microsoft\crypto\rsa\machinekeys\08e575673cce10c72090304839888e02_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
- %TEMP%\ryukreadme.html
- D:\ryukreadme.html
- D:\$recycle.bin\ryukreadme.html
- D:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\ryukreadme.html
- C:\ryukreadme.html
- C:\documents and settings\ryukreadme.html
- %ALLUSERSPROFILE%\ryukreadme.html
- %ALLUSERSPROFILE%\adobe\ryukreadme.html
- %ALLUSERSPROFILE%\adobe\arm\ryukreadme.html
- %ALLUSERSPROFILE%\adobe\arm\reader_15.007.20033\ryukreadme.html
- %ALLUSERSPROFILE%\adobe\arm\reader_15.008.20082\ryukreadme.html
- %ALLUSERSPROFILE%\adobe\arm\s\ryukreadme.html
- %ALLUSERSPROFILE%\adobe\arm\s\10428\ryukreadme.html
- %ALLUSERSPROFILE%\adobe\arm\{291aa914-a987-4ce9-bd63-ac0a92d435e5}\ryukreadme.html
- %ALLUSERSPROFILE%\adobe\setup\ryukreadme.html
- %ALLUSERSPROFILE%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\ryukreadme.html
- %ALLUSERSPROFILE%\adobe\arm\reader_15.007.20033\readerdcmanifest.msi
- %ALLUSERSPROFILE%\application data\application data\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\acroread.msi
- %ALLUSERSPROFILE%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\data1.cab
- %ALLUSERSPROFILE%\application data\application data\application data\adobe\arm\s\armmanifest.msi
- %ALLUSERSPROFILE%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\acrordrdcupd1500820082.msp
- %ALLUSERSPROFILE%\application data\application data\adobe\arm\reader_15.007.20033\acrordrdcupd1500920077.msp
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\appli...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\docum...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\micro...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\oracl...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\start...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\netframework...
- %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\assistance\client\1.0\en-us\h...
- from %ALLUSERSPROFILE%\adobe\arm\reader_15.007.20033\readerdcmanifest.msi to %ALLUSERSPROFILE%\adobe\arm\reader_15.007.20033\readerdcmanifest.msi.ryk
- from %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{2af972c... to %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{2af972c...
- from %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{0f12c81... to %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{0f12c81...
- from %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{e46eca4... to %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{e46eca4...
- from %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{51adbf1... to %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{51adbf1...
- from %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{f65db02... to %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{f65db02...
- from %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{f0080ca... to %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{f0080ca...
- from %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{dde2682... to %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{dde2682...
- from %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{b55f720... to %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{b55f720...
- from %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{a219961... to %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{a219961...
- from %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{6c95b50... to %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{6c95b50...
- from %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{615bc16... to %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{615bc16...
- from %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{35459b2... to %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{35459b2...
- from %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{33d1fd9... to %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{33d1fd9...
- from %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{74d0e5d... to %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{74d0e5d...
- from %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{01db25f... to %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{01db25f...
- from %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\windows defe... to %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\windows defe...
- from %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\officesoftwa... to %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\officesoftwa...
- from %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\oracl... to %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\oracl...
- from %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\documents\my music\sam... to %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\documents\my music\sam...
- from %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\documents\my pictures\... to %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\documents\my pictures\...
- from %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\assistance\c... to %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\assistance\c...
- from %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\micro... to %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\micro...
- from %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\docum... to %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\docum...
- from %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\appli... to %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\appli...
- from %ALLUSERSPROFILE%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\acrordrdcupd1500820082.msp to %ALLUSERSPROFILE%\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\acrordrdcupd1500820082.msp.ryk
- from %ALLUSERSPROFILE%\application data\application data\adobe\arm\reader_15.007.20033\acrordrdcupd1500920077.msp to %ALLUSERSPROFILE%\application data\application data\adobe\arm\reader_15.007.20033\acrordrdcupd1500920077.msp.ryk
- from %ALLUSERSPROFILE%\application data\application data\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\acroread.msi to %ALLUSERSPROFILE%\application data\application data\adobe\setup\{ac76ba86-7ad7-1033-7b44-ac0f074e4100}\acroread.msi.ryk
- from %ALLUSERSPROFILE%\application data\application data\application data\adobe\arm\s\armmanifest.msi to %ALLUSERSPROFILE%\application data\application data\application data\adobe\arm\s\armmanifest.msi.ryk
- from %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft help\ms.netf... to %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft help\ms.netf...
- from %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{ce085a7... to %ALLUSERSPROFILE%\application data\application data\application data\application data\application data\application data\application data\application data\application data\package cache\{ce085a7...
- '<LOCALNET>.17.1':7
- '22#.0.0.22':7
- '22#.0.0.252':7
- '23#.#55.255.250':7
- 'C:\users\public\xmahg.exe' "<Full path to file>"
- 'C:\users\public\hvvugyv.exe' 8 LAN
- 'C:\users\public\xmahg.exe' "<Full path to file>"' (with hidden window)
- 'C:\users\public\hvvugyv.exe' 8 LAN' (with hidden window)
- '<SYSTEM32>\net.exe' stop "audioendpointbuilder" /y' (with hidden window)
- '<SYSTEM32>\net.exe' stop "samss" /y' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C REG ADD "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "svchos" /t REG_SZ /d "<SYSTEM32>\Dwm.exe" /f' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C REG ADD "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "svchos" /t REG_SZ /d "C:\users\Public\xmAhg.exe" /f' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C REG ADD "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "svchos" /t REG_SZ /d "C:\users\Public\HVvUgYV.exe" /f' (with hidden window)
- '<SYSTEM32>\net1.exe' stop "audioendpointbuilder" /y
- '<SYSTEM32>\net1.exe' stop "samss" /y
- '<SYSTEM32>\cmd.exe' /C REG ADD "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "svchos" /t REG_SZ /d "<SYSTEM32>\Dwm.exe" /f
- '<SYSTEM32>\cmd.exe' /C REG ADD "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "svchos" /t REG_SZ /d "C:\users\Public\xmAhg.exe" /f
- '<SYSTEM32>\reg.exe' ADD "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "svchos" /t REG_SZ /d "<SYSTEM32>\Dwm.exe" /f
- '<SYSTEM32>\reg.exe' ADD "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "svchos" /t REG_SZ /d "C:\users\Public\xmAhg.exe" /f
- '<SYSTEM32>\cmd.exe' /C REG ADD "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "svchos" /t REG_SZ /d "C:\users\Public\HVvUgYV.exe" /f
- '<SYSTEM32>\reg.exe' ADD "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "svchos" /t REG_SZ /d "C:\users\Public\HVvUgYV.exe" /f