Technical Information
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'firefox' = '"%ALLUSERSPROFILE%\Microsoft Toolkit\firefox.exe"'
- [<HKLM>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe, "%ALLUSERSPROFILE%\Microsoft Toolkit\firefox.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'spoolsv' = '"C:\Far2\Encyclopedia\tap\spoolsv.exe"'
- [<HKLM>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe, "%ALLUSERSPROFILE%\Microsoft Toolkit\firefox.exe", "C:\Far2\Encyclopedia\tap\spoolsv.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'lsass' = '"C:\Far2\Documentation\eng\lsass.exe"'
- [<HKLM>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe, "%ALLUSERSPROFILE%\Microsoft Toolkit\firefox.exe", "C:\Far2\Encyclopedia\tap\spoolsv.exe", "C:\Far2\Docum...
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'smss' = '"%ALLUSERSPROFILE%\Microsoft Toolkit\smss.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'taskhost' = '"C:\totalcmd\LANGUAGE\taskhost.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'services' = '"%WINDIR%\AppPatch\services.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] '<File name>' = '"%ALLUSERSPROFILE%\Oracle\Java\javapath\<File name>.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'winlogon' = '"%WINDIR%\Resources\Ease of Access Themes\winlogon.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'dwm' = '"C:\Documents and Settings\dwm.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'firefox' = '"%ProgramFiles%\UpdaterUI\firefox.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'firefox' = '"%ProgramFiles%\svcntaux\firefox.exe"'
- <SYSTEM32>\tasks\l72xfirefox
- <SYSTEM32>\tasks\vzwh<File name>
- <SYSTEM32>\tasks\dblo<File name>
- <SYSTEM32>\tasks\lggg<File name>
- <SYSTEM32>\tasks\<File name>
- <SYSTEM32>\tasks\kxsywinlogon
- <SYSTEM32>\tasks\7mxrwinlogon
- <SYSTEM32>\tasks\pofawinlogon
- <SYSTEM32>\tasks\vjsolsass
- <SYSTEM32>\tasks\winlogon
- <SYSTEM32>\tasks\osxgdwm
- <SYSTEM32>\tasks\bt28dwm
- <SYSTEM32>\tasks\dwm
- <SYSTEM32>\tasks\umr6firefox
- <SYSTEM32>\tasks\dmvdfirefox
- <SYSTEM32>\tasks\2grtfirefox
- <SYSTEM32>\tasks\otdlfirefox
- <SYSTEM32>\tasks\goqfservices
- <SYSTEM32>\tasks\services
- <SYSTEM32>\tasks\gg7iservices
- <SYSTEM32>\tasks\nrwqservices
- <SYSTEM32>\tasks\taskhost
- <SYSTEM32>\tasks\oyg0firefox
- <SYSTEM32>\tasks\firefox
- <SYSTEM32>\tasks\iqgtspoolsv
- <SYSTEM32>\tasks\qgjuspoolsv
- <SYSTEM32>\tasks\ska6spoolsv
- <SYSTEM32>\tasks\spoolsv
- <SYSTEM32>\tasks\gk95lsass
- <SYSTEM32>\tasks\3hcvfirefox
- <SYSTEM32>\tasks\l219dwm
- <SYSTEM32>\tasks\ekwdlsass
- <SYSTEM32>\tasks\kfa8smss
- <SYSTEM32>\tasks\hfj2smss
- <SYSTEM32>\tasks\dryasmss
- <SYSTEM32>\tasks\smss
- <SYSTEM32>\tasks\q13ctaskhost
- <SYSTEM32>\tasks\a2pttaskhost
- <SYSTEM32>\tasks\fzegtaskhost
- <SYSTEM32>\tasks\6u1xfirefox
- <SYSTEM32>\tasks\lsass
- <SYSTEM32>\tasks\azx0firefox
- User Account Control (UAC)
- %ALLUSERSPROFILE%\microsoft toolkit\firefox.exe
- C:\far2\encyclopedia\tap\rcx3749.tmp
- C:\far2\encyclopedia\tap\rcx37f6.tmp
- C:\far2\documentation\eng\rcx3aa5.tmp
- C:\far2\documentation\eng\rcx3b42.tmp
- %ALLUSERSPROFILE%\microsoft toolkit\rcx3df2.tmp
- %ALLUSERSPROFILE%\microsoft toolkit\rcx3eae.tmp
- C:\totalcmd\language\rcx415d.tmp
- C:\totalcmd\language\rcx420a.tmp
- %WINDIR%\apppatch\c5b4cb5e9653cc
- %WINDIR%\apppatch\rcx44c9.tmp
- %ALLUSERSPROFILE%\oracle\java\javapath\rcx4825.tmp
- %ALLUSERSPROFILE%\oracle\java\javapath\rcx48d1.tmp
- %WINDIR%\resources\ease of access themes\rcx4b71.tmp
- %WINDIR%\resources\ease of access themes\rcx4c1e.tmp
- C:\documents and settings\rcx4ebe.tmp
- C:\documents and settings\rcx4f6a.tmp
- %ProgramFiles%\updaterui\rcx5229.tmp
- %ProgramFiles%\updaterui\rcx52e5.tmp
- %ALLUSERSPROFILE%\microsoft toolkit\rcx33fd.tmp
- %ALLUSERSPROFILE%\microsoft toolkit\rcx34a9.tmp
- <Current directory>\rcx31ca.tmp
- <Current directory>\rcx317b.tmp
- %ProgramFiles%\svcntaux\0fc223bdacedc3
- C:\far2\encyclopedia\tap\spoolsv.exe
- C:\far2\encyclopedia\tap\f3b6ecef712a24
- C:\far2\documentation\eng\lsass.exe
- C:\far2\documentation\eng\6203df4a6bafc7
- %ALLUSERSPROFILE%\microsoft toolkit\smss.exe
- %ALLUSERSPROFILE%\microsoft toolkit\69ddcba757bf72
- C:\totalcmd\language\taskhost.exe
- C:\totalcmd\language\b75386f1303e64
- %ProgramFiles%\svcntaux\rcx5595.tmp
- %WINDIR%\apppatch\rcx4575.tmp
- %WINDIR%\apppatch\services.exe
- %ALLUSERSPROFILE%\oracle\java\javapath\c7304b5bf0c5cb
- %WINDIR%\resources\ease of access themes\winlogon.exe
- %WINDIR%\resources\ease of access themes\cc11b995f2a76d
- C:\documents and settings\dwm.exe
- C:\documents and settings\6cb0b6c459d5d3
- %ProgramFiles%\updaterui\firefox.exe
- %ProgramFiles%\updaterui\0fc223bdacedc3
- %ProgramFiles%\svcntaux\firefox.exe
- %ALLUSERSPROFILE%\microsoft toolkit\0fc223bdacedc3
- %ALLUSERSPROFILE%\oracle\java\javapath\<File name>.exe
- %ProgramFiles%\svcntaux\rcx5641.tmp
- <Full path to file>
- %ALLUSERSPROFILE%\microsoft toolkit\firefox.exe
- C:\far2\encyclopedia\tap\spoolsv.exe
- C:\far2\documentation\eng\lsass.exe
- %ALLUSERSPROFILE%\microsoft toolkit\smss.exe
- C:\totalcmd\language\taskhost.exe
- %WINDIR%\apppatch\services.exe
- %ALLUSERSPROFILE%\oracle\java\javapath\<File name>.exe
- %WINDIR%\resources\ease of access themes\winlogon.exe
- C:\documents and settings\dwm.exe
- %ProgramFiles%\updaterui\firefox.exe
- %ProgramFiles%\svcntaux\firefox.exe
- from <Current directory>\rcx31ca.tmp to <Full path to file>
- from %ProgramFiles%\updaterui\rcx52e5.tmp to %ProgramFiles%\updaterui\firefox.exe
- from %ProgramFiles%\updaterui\rcx5229.tmp to %ProgramFiles%\updaterui\firefox.exe
- from C:\documents and settings\rcx4f6a.tmp to C:\documents and settings\dwm.exe
- from C:\documents and settings\rcx4ebe.tmp to C:\documents and settings\dwm.exe
- from %WINDIR%\resources\ease of access themes\rcx4c1e.tmp to %WINDIR%\resources\ease of access themes\winlogon.exe
- from %WINDIR%\resources\ease of access themes\rcx4b71.tmp to %WINDIR%\resources\ease of access themes\winlogon.exe
- from %ALLUSERSPROFILE%\oracle\java\javapath\rcx48d1.tmp to %ALLUSERSPROFILE%\oracle\java\javapath\<File name>.exe
- from %ALLUSERSPROFILE%\oracle\java\javapath\rcx4825.tmp to %ALLUSERSPROFILE%\oracle\java\javapath\<File name>.exe
- from %WINDIR%\apppatch\rcx4575.tmp to %WINDIR%\apppatch\services.exe
- from %ProgramFiles%\svcntaux\rcx5595.tmp to %ProgramFiles%\svcntaux\firefox.exe
- from %WINDIR%\apppatch\rcx44c9.tmp to %WINDIR%\apppatch\services.exe
- from C:\totalcmd\language\rcx415d.tmp to C:\totalcmd\language\taskhost.exe
- from %ALLUSERSPROFILE%\microsoft toolkit\rcx3eae.tmp to %ALLUSERSPROFILE%\microsoft toolkit\smss.exe
- from %ALLUSERSPROFILE%\microsoft toolkit\rcx3df2.tmp to %ALLUSERSPROFILE%\microsoft toolkit\smss.exe
- from C:\far2\documentation\eng\rcx3b42.tmp to C:\far2\documentation\eng\lsass.exe
- from C:\far2\documentation\eng\rcx3aa5.tmp to C:\far2\documentation\eng\lsass.exe
- from C:\far2\encyclopedia\tap\rcx37f6.tmp to C:\far2\encyclopedia\tap\spoolsv.exe
- from C:\far2\encyclopedia\tap\rcx3749.tmp to C:\far2\encyclopedia\tap\spoolsv.exe
- from %ALLUSERSPROFILE%\microsoft toolkit\rcx34a9.tmp to %ALLUSERSPROFILE%\microsoft toolkit\firefox.exe
- from %ALLUSERSPROFILE%\microsoft toolkit\rcx33fd.tmp to %ALLUSERSPROFILE%\microsoft toolkit\firefox.exe
- from C:\totalcmd\language\rcx420a.tmp to C:\totalcmd\language\taskhost.exe
- from %ProgramFiles%\svcntaux\rcx5641.tmp to %ProgramFiles%\svcntaux\firefox.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath '<Full path to file>'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath 'C:\Far2\Encyclopedia\tap\spoolsv.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath 'C:\Far2\Documentation\eng\lsass.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath 'C:\totalcmd\LANGUAGE\taskhost.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath '%WINDIR%\AppPatch\services.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath '%ALLUSERSPROFILE%\Oracle\Java\javapath\<File name>.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath '%ProgramFiles%\UpdaterUI\firefox.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath '%ProgramFiles%\svcntaux\firefox.exe'
- '%ALLUSERSPROFILE%\microsoft toolkit\smss.exe'
- '%ALLUSERSPROFILE%\microsoft toolkit\smss.exe' ' (with hidden window)
- '<SYSTEM32>\schtasks.exe' /create /tn "L72xfirefox" /sc MINUTE /mo 10 /tr "'%ALLUSERSPROFILE%\Microsoft Toolkit\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "<File name>" /sc MINUTE /mo 13 /tr "'%ALLUSERSPROFILE%\Oracle\Java\javapath\<File name>.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "kXsYwinlogon" /sc MINUTE /mo 8 /tr "'%WINDIR%\Resources\Ease of Access Themes\winlogon.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "7Mxrwinlogon" /sc ONLOGON /tr "'%WINDIR%\Resources\Ease of Access Themes\winlogon.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "pofawinlogon" /sc ONSTART /tr "'%WINDIR%\Resources\Ease of Access Themes\winlogon.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "winlogon" /sc MINUTE /mo 13 /tr "'%WINDIR%\Resources\Ease of Access Themes\winlogon.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "l219dwm" /sc MINUTE /mo 5 /tr "'C:\Documents and Settings\dwm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "oSXgdwm" /sc ONLOGON /tr "'C:\Documents and Settings\dwm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "bT28dwm" /sc ONSTART /tr "'C:\Documents and Settings\dwm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "VzWh<File name>" /sc ONLOGON /tr "'%ALLUSERSPROFILE%\Oracle\Java\javapath\<File name>.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "lggG<File name>" /sc ONSTART /tr "'%ALLUSERSPROFILE%\Oracle\Java\javapath\<File name>.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "dwm" /sc MINUTE /mo 11 /tr "'C:\Documents and Settings\dwm.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "2grTfirefox" /sc ONSTART /tr "'%ProgramFiles%\UpdaterUI\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefox" /sc MINUTE /mo 8 /tr "'%ProgramFiles%\UpdaterUI\firefox.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "oTDLfirefox" /sc MINUTE /mo 5 /tr "'%ProgramFiles%\svcntaux\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "3HCvfirefox" /sc ONLOGON /tr "'%ProgramFiles%\svcntaux\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "aZx0firefox" /sc ONSTART /tr "'%ProgramFiles%\svcntaux\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefox" /sc MINUTE /mo 5 /tr "'%ProgramFiles%\svcntaux\firefox.exe'" /f
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath '%ALLUSERSPROFILE%\Microsoft Toolkit\firefox.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath '%ALLUSERSPROFILE%\Microsoft Toolkit\smss.exe'
- '<SYSTEM32>\schtasks.exe' /create /tn "uMr6firefox" /sc MINUTE /mo 8 /tr "'%ProgramFiles%\UpdaterUI\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "dmVDfirefox" /sc ONLOGON /tr "'%ProgramFiles%\UpdaterUI\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "DBLo<File name>" /sc MINUTE /mo 7 /tr "'%ALLUSERSPROFILE%\Oracle\Java\javapath\<File name>.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "services" /sc MINUTE /mo 13 /tr "'%WINDIR%\AppPatch\services.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "goQFservices" /sc ONSTART /tr "'%WINDIR%\AppPatch\services.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "oYG0firefox" /sc ONSTART /tr "'%ALLUSERSPROFILE%\Microsoft Toolkit\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefox" /sc MINUTE /mo 9 /tr "'%ALLUSERSPROFILE%\Microsoft Toolkit\firefox.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "IQgtspoolsv" /sc MINUTE /mo 8 /tr "'C:\Far2\Encyclopedia\tap\spoolsv.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "qGjuspoolsv" /sc ONLOGON /tr "'C:\Far2\Encyclopedia\tap\spoolsv.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "skA6spoolsv" /sc ONSTART /tr "'C:\Far2\Encyclopedia\tap\spoolsv.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "spoolsv" /sc MINUTE /mo 6 /tr "'C:\Far2\Encyclopedia\tap\spoolsv.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "Gk95lsass" /sc MINUTE /mo 9 /tr "'C:\Far2\Documentation\eng\lsass.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "EKwdlsass" /sc ONLOGON /tr "'C:\Far2\Documentation\eng\lsass.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "VJSolsass" /sc ONSTART /tr "'C:\Far2\Documentation\eng\lsass.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "6U1xfirefox" /sc ONLOGON /tr "'%ALLUSERSPROFILE%\Microsoft Toolkit\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "lsass" /sc MINUTE /mo 13 /tr "'C:\Far2\Documentation\eng\lsass.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "HfJ2smss" /sc ONLOGON /tr "'%ALLUSERSPROFILE%\Microsoft Toolkit\smss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "dryAsmss" /sc ONSTART /tr "'%ALLUSERSPROFILE%\Microsoft Toolkit\smss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "smss" /sc MINUTE /mo 12 /tr "'%ALLUSERSPROFILE%\Microsoft Toolkit\smss.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "Q13Ctaskhost" /sc MINUTE /mo 9 /tr "'C:\totalcmd\LANGUAGE\taskhost.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "A2pttaskhost" /sc ONLOGON /tr "'C:\totalcmd\LANGUAGE\taskhost.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "FzEGtaskhost" /sc ONSTART /tr "'C:\totalcmd\LANGUAGE\taskhost.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "taskhost" /sc MINUTE /mo 10 /tr "'C:\totalcmd\LANGUAGE\taskhost.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "nRwqservices" /sc MINUTE /mo 13 /tr "'%WINDIR%\AppPatch\services.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "GG7Iservices" /sc ONLOGON /tr "'%WINDIR%\AppPatch\services.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "kfA8smss" /sc MINUTE /mo 5 /tr "'%ALLUSERSPROFILE%\Microsoft Toolkit\smss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath '%WINDIR%\Resources\Ease of Access Themes\winlogon.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath 'C:\Documents and Settings\dwm.exe'