Technical Information
- <SYSTEM32>\tasks\waijo
- %HOMEPATH%\desktop\000814251_video_01.avi
- %HOMEPATH%\desktop\508softwareandos.doc
- %HOMEPATH%\desktop\aoc_saq_d_v3_merchant.docx
- %HOMEPATH%\desktop\dashborder_120.bmp
- %HOMEPATH%\desktop\dashborder_192.bmp
- %HOMEPATH%\desktop\default.bmp
- %HOMEPATH%\desktop\dial.bmp
- %HOMEPATH%\desktop\split.avi
- %HOMEPATH%\desktop\toolbar.bmp
- %APPDATA%\other\pawje.exe
- %LOCALAPPDATA%\microsoft\windows mail\stationery\tiki.gif.schw
- %LOCALAPPDATA%\microsoft\windows mail\stationery\stucco.gif.schw
- %LOCALAPPDATA%\microsoft\windows mail\stationery\grid_(inch).wmf.schw
- %LOCALAPPDATA%\microsoft\windows mail\stationery\grid_(cm).wmf.schw
- %LOCALAPPDATA%\microsoft\windows mail\stationery\connectivity.gif.schw
- %LOCALAPPDATA%\microsoft\windows mail\stationery\cave_drawings.gif.schw
- %LOCALAPPDATA%\microsoft\windows mail\backup\new\windowsmail.pat.schw
- %LOCALAPPDATA%\microsoft\windows mail\windowsmail.pat.schw
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\qkr46vql\favicon[1].ico.schw
- %LOCALAPPDATA%\microsoft\internet explorer\brndlog.txt.schw
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\main.js.schw
- %LOCALAPPDATA%\google\chrome\user data\default\google profile.ico.schw
- C:\users\public\music\sample music\sleep away.mp3.schw
- C:\users\public\music\sample music\maid with the flaxen hair.mp3.schw
- C:\users\public\music\sample music\kalimba.mp3.schw
- %ALLUSERSPROFILE%\microsoft\windows nt\msfax\virtualinbox\en-us\welcomefax.tif.schw
- %ALLUSERSPROFILE%\microsoft\windows\caches\{ddf571f2-be98-426d-8288-1a9a39c3fda2}.2.ver0x0000000000000002.db.schw
- %ALLUSERSPROFILE%\microsoft\windows\caches\{7058fba7-4345-4f87-a783-212c3dc6f95f}.2.ver0x0000000000000001.db.schw
- %ALLUSERSPROFILE%\microsoft\windows\caches\{6af0698e-d558-4f6e-9b3c-3716689af493}.2.ver0x000000000000000b.db.schw
- %ALLUSERSPROFILE%\microsoft\windows\caches\{6af0698e-d558-4f6e-9b3c-3716689af493}.2.ver0x000000000000000a.db.schw
- %ALLUSERSPROFILE%\microsoft\windows\caches\{4e4260a4-7e39-442e-bc22-7ff751d1c161}.2.ver0x0000000000000002.db.schw
- %ALLUSERSPROFILE%\microsoft\windows\caches\{40fc8d7d-05ed-4feb-b03b-6c100659ef5c}.2.ver0x0000000000000001.db.schw
- %ALLUSERSPROFILE%\microsoft\windows\caches\cversions.2.db.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile44.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile43.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile42.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile41.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile40.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile39.bmp.schw
- %LOCALAPPDATA%\microsoft\windows mail\stationery\wrinkled_paper.gif.schw
- %TEMP%\dd_dotnetfx40_full_x86_x64_decompression_log.txt.schw
- %TEMP%\dd_ndp48-x86-x64-allos-enu_decompression_log.txt.schw
- %TEMP%\dd_setuputility.txt.schw
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\prefs.js.schw
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\pkcs11.txt.schw
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\alternateservices.txt.schw
- %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\gmp-widevinecdm\4.10.1582.2\license.txt.schw
- %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\user.js.schw
- %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\trrblacklist.txt.schw
- %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\sitesecurityservicestate.txt.schw
- %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\securitypreloadstate.txt.schw
- %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\prefs.js.schw
- %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\pkcs11.txt.schw
- %APPDATA%\mozilla\firefox\profiles\yfwt7ezn.default-release-1\alternateservices.txt.schw
- %APPDATA%\mozilla\firefox\profiles\bcjnbgva.default\user.js.schw
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\user.js.schw
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\trrblacklist.txt.schw
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\securitypreloadstate.txt.schw
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\sitesecurityservicestate.txt.schw
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\prefs.js.schw
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\pkcs11.txt.schw
- %APPDATA%\mozilla\firefox\profiles\0j9e9tku.default-release\alternateservices.txt.schw
- %LOCALAPPDATA%low\microsoft\internet explorer\services\search_{0633ee93-d776-472f-a0ff-e1416b8b2e3a}.ico.schw
- %TEMP%\microsoft visual c++ 2010 x86 redistributable setup_20220928_165304913-msi_vc_red.msi.txt.schw
- %TEMP%\microsoft visual c++ 2010 x64 redistributable setup_20220928_165235616-msi_vc_red.msi.txt.schw
- %TEMP%\microsoft visual c++ 2010 x64 redistributable setup_20220928_164850616-msi_vc_red.msi.txt.schw
- %TEMP%\microsoft .net framework 4 setup_20230531_155457219-msi_netfx_extended_x64.msi.txt.schw
- %TEMP%\microsoft .net framework 4 setup_20230531_155457219-msi_netfx_core_x64.msi.txt.schw
- %TEMP%\fxsapidebuglogfile.txt.schw
- %TEMP%\dd_wcf_ca_smci_20230531_225945_094.txt.schw
- %TEMP%\dd_wcf_ca_smci_20230531_225943_157.txt.schw
- %TEMP%\dd_vcredistui7a3c.txt.schw
- %TEMP%\dd_vcredistmsi7a3c.txt.schw
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\securitypreloadstate.txt.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile38.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile37.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile36.bmp.schw
- %ALLUSERSPROFILE%\microsoft\office\assetlibrary.ico.schw
- %ALLUSERSPROFILE%\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\en-us\resource.xml.schw
- %ALLUSERSPROFILE%\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\tasks.xml.schw
- %ALLUSERSPROFILE%\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\scan_settings.ico.schw
- %ALLUSERSPROFILE%\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\scan_property.ico.schw
- %ALLUSERSPROFILE%\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\scan_.ico.schw
- %ALLUSERSPROFILE%\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\print_queue.ico.schw
- %ALLUSERSPROFILE%\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\print_property.ico.schw
- %ALLUSERSPROFILE%\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\print_pref.ico.schw
- %ALLUSERSPROFILE%\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\folder.ico.schw
- %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\en-us\resource.xml.schw
- %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\wmp.ico.schw
- %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\tasks.xml.schw
- %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\sync.ico.schw
- %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\settings.ico.schw
- %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\ringtones.ico.schw
- %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml.schw
- %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pictures.ico.schw
- %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\netfol.ico.schw
- %ALLUSERSPROFILE%\microsoft\device stage\task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\folder.ico.schw
- %ALLUSERSPROFILE%\microsoft\device stage\device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png.schw
- %ALLUSERSPROFILE%\microsoft\device stage\device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml.schw
- %ALLUSERSPROFILE%\microsoft\device stage\device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png.schw
- %ALLUSERSPROFILE%\microsoft\device stage\device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png.schw
- %ALLUSERSPROFILE%\microsoft\device stage\device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png.schw
- %ALLUSERSPROFILE%\microsoft\device stage\device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png.schw
- %ALLUSERSPROFILE%\microsoft\device stage\device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml.schw
- %ALLUSERSPROFILE%\microsoft\device stage\device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png.schw
- %APPDATA%\other\awiem.bat
- %ALLUSERSPROFILE%\microsoft\office\documentrepository.ico.schw
- %ALLUSERSPROFILE%\microsoft\office\mysharepoints.ico.schw
- %ALLUSERSPROFILE%\microsoft\office\mysite.ico.schw
- %ALLUSERSPROFILE%\microsoft\office\sharepointportalsite.ico.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile34.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile33.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile32.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile31.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile30.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile29.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile28.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile27.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile26.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile25.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile24.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile23.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile22.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile21.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile19.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile20.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile18.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile17.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile16.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile15.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile14.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile13.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile12.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile11.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile10.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\user.bmp.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\guest.bmp.schw
- %ALLUSERSPROFILE%\microsoft\rac\statedata\racdatabase.sdf.schw
- %ALLUSERSPROFILE%\microsoft\rac\publisheddata\racwmidatabase.sdf.schw
- %ALLUSERSPROFILE%\microsoft\office\sharepointteamsite.ico.schw
- %ALLUSERSPROFILE%\microsoft\user account pictures\default pictures\usertile35.bmp.schw
- %APPDATA%\thunderbird\profiles\npsdfqy3.default-release\sitesecurityservicestate.txt.schw
- %LOCALAPPDATA%\Microsoft\Windows\Explorer\thumbcache_idx.db
- %LOCALAPPDATA%\Microsoft\Windows\Explorer\thumbcache_32.db
- %LOCALAPPDATA%\Microsoft\Windows\Explorer\thumbcache_96.db
- %LOCALAPPDATA%\Microsoft\Windows\Explorer\thumbcache_256.db
- %LOCALAPPDATA%\Microsoft\Windows\Explorer\thumbcache_1024.db
- %LOCALAPPDATA%\Microsoft\Windows\Explorer\thumbcache_sr.db
- '%APPDATA%\other\pawje.exe'
- '%WINDIR%\syswow64\cmd.exe' /c %APPDATA%\Other\awiem.bat' (with hidden window)
- '%APPDATA%\other\pawje.exe' ' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c %APPDATA%\Other\awiem.bat
- '%WINDIR%\syswow64\schtasks.exe' /Create /SC MINUTE /MO 1 /TN waijo /tr %APPDATA%\Other\pawje.exe
- '<SYSTEM32>\taskeng.exe' {7E1099BF-630E-4343-9C47-3A3E15F7E7E8} S-1-5-21-1238866942-1249195528-555854008-1000:adimpf\user:Interactive:[1]