Technical Information
- [HKCU\Software\Classes\discord-1150373996290904174\shell\open\command] '' = '<Full path to file>'
- '<SYSTEM32>\taskkill.exe' /F /IM adb.exe
- '<SYSTEM32>\taskkill.exe' /F /im AndroidEmulatorEx.exe
- '<SYSTEM32>\taskkill.exe' /F /IM AndroidProcess.exe
- '<SYSTEM32>\taskkill.exe' /F /im AndroidEmulator.exe
- '<SYSTEM32>\taskkill.exe' /F /IM ProjectTitan.exe
- '<SYSTEM32>\taskkill.exe' /F /im Gameloop.exe
- '<SYSTEM32>\taskkill.exe' /F /im AndroidEmulatorEn.exe
- '<SYSTEM32>\taskkill.exe' /F /im AppMarket.exe
- '<SYSTEM32>\taskkill.exe' /F /im cmd.exe
- '<SYSTEM32>\net.exe' stop aow_drv
- '<SYSTEM32>\net.exe' stop AndroidKernel
- <SYSTEM32>\cmd.exe
- %WINDIR%\temp\cab3513.tmp
- %WINDIR%\temp\tar3514.tmp
- %WINDIR%\temp\cab70fc.tmp
- %WINDIR%\temp\tar70fd.tmp
- %WINDIR%\temp\cabb474.tmp
- %WINDIR%\temp\tarb484.tmp
- %WINDIR%\temp\cabce3c.tmp
- %WINDIR%\temp\tarce3d.tmp
- %WINDIR%\temp\cabe3d1.tmp
- %WINDIR%\temp\tare3d2.tmp
- %WINDIR%\temp\cabe421.tmp
- %WINDIR%\temp\tare422.tmp
- %WINDIR%\temp\cab3513.tmp
- %WINDIR%\temp\tar3514.tmp
- %WINDIR%\temp\cab70fc.tmp
- %WINDIR%\temp\tar70fd.tmp
- %WINDIR%\temp\cabb474.tmp
- %WINDIR%\temp\tarb484.tmp
- %WINDIR%\temp\cabce3c.tmp
- %WINDIR%\temp\tarce3d.tmp
- %WINDIR%\temp\cabe3d1.tmp
- %WINDIR%\temp\tare3d2.tmp
- %WINDIR%\temp\cabe421.tmp
- %WINDIR%\temp\tare422.tmp
- 'localhost':49184
- 'localhost':49186
- 'gi##ub.com':443
- 'oc##.#ectigo.com':80
- 'localhost':49193
- 'localhost':49195
- 'localhost':49198
- 'ra#.####ubusercontent.com':443
- http://oc##.#ectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTPlNxcMEqnlIVyH5VuZ4lawhZX3QQU9oUKOxGG4QR9DqoLLNLuzGR7e64CEE4o94a2bBo7lCzSxA63QqU%3D
- 'localhost':49184
- 'localhost':49186
- 'localhost':49187
- 'gi##ub.com':443
- 'localhost':49193
- 'localhost':49195
- 'localhost':49196
- 'localhost':49198
- 'localhost':49199
- 'ra#.####ubusercontent.com':443
- DNS ASK gi##ub.com
- DNS ASK oc##.#ectigo.com
- DNS ASK ra#.####ubusercontent.com
- ClassName: '' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall firewall delete rule name=ven
- '<SYSTEM32>\cmd.exe' /c net stop aow_drv
- '<SYSTEM32>\find.exe' /i /v "certutil"
- '<SYSTEM32>\cmd.exe' /c sc delete aow_drv
- '<SYSTEM32>\netsh.exe' advfirewall firewall delete rule name = port
- '<SYSTEM32>\netsh.exe' advfirewall firewall delete rule name = Xbox
- '<SYSTEM32>\netsh.exe' advfirewall firewall delete rule name = ip
- '<SYSTEM32>\cmd.exe' /c sc stop driver
- '<SYSTEM32>\cmd.exe' /c sc stop venbp
- '<SYSTEM32>\net1.exe' stop aow_drv
- '<SYSTEM32>\cmd.exe' /c sc stop UniFairy_x64
- '<SYSTEM32>\cmd.exe' /c sc delete driver
- '<SYSTEM32>\net1.exe' stop AndroidKernel
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall firewall delete rule name = Xbox
- '<SYSTEM32>\cmd.exe' /c sc delete venbp
- '<SYSTEM32>\sc.exe' delete aow_drv
- '<SYSTEM32>\sc.exe' stop venbp
- '<SYSTEM32>\sc.exe' delete AndroidKernel
- '<SYSTEM32>\sc.exe' stop driver
- '<SYSTEM32>\sc.exe' delete venbp
- '<SYSTEM32>\sc.exe' delete driver
- '<SYSTEM32>\sc.exe' stop UniFairy_x64
- '<SYSTEM32>\cmd.exe' /c rundll32 user32.dll,MessageBeep
- '<SYSTEM32>\sc.exe' delete UniFairy_x64
- '<SYSTEM32>\cmd.exe' /c sc delete AndroidKernel
- '<SYSTEM32>\cmd.exe' /c cls
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM AndroidProcess.exe
- '<SYSTEM32>\cmd.exe' /c certutil -hashfile "<Full path to file>" MD5 | find /i /v "md5" | find /i /v "certutil"
- '<SYSTEM32>\certutil.exe' -hashfile "<Full path to file>" MD5
- '<SYSTEM32>\cmd.exe' /c sc delete UniFairy_x64
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall firewall delete rule name = ip
- '<SYSTEM32>\cmd.exe' /c net stop AndroidKernel
- '<SYSTEM32>\netsh.exe' advfirewall firewall delete rule name=island
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall firewall delete rule name=island
- '<SYSTEM32>\cmd.exe' /c adb kill-server
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM adb.exe
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM ProjectTitan.exe
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall firewall delete rule name=ip
- '<SYSTEM32>\netsh.exe' advfirewall firewall delete rule name=ven
- '<SYSTEM32>\cmd.exe' /c taskkill /F /im AndroidEmulator.exe
- '<SYSTEM32>\netsh.exe' advfirewall firewall delete rule name=ip
- '<SYSTEM32>\cmd.exe' /c taskkill /F /im AndroidEmulatorEx.exe
- '<SYSTEM32>\cmd.exe' /c taskkill /F /im AndroidEmulatorEn.exe
- '<SYSTEM32>\find.exe' /i /v "md5"
- '<SYSTEM32>\cmd.exe' /c taskkill /F /im Gameloop.exe
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall firewall delete rule name = port
- '<SYSTEM32>\cmd.exe' /c taskkill /F /im AppMarket.exe
- '<SYSTEM32>\cmd.exe' /c taskkill /F /im cmd.exe
- '<SYSTEM32>\rundll32.exe' user32.dll,MessageBeep
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM adb.exe' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c net stop aow_drv' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c adb kill-server' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /im cmd.exe' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall firewall delete rule name=island' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c sc delete AndroidKernel' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall firewall delete rule name = Xbox' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall firewall delete rule name=ip' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /im AndroidEmulatorEn.exe' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM AndroidProcess.exe' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c rundll32 user32.dll,MessageBeep' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c net stop AndroidKernel' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c sc delete aow_drv' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c sc delete UniFairy_x64' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c sc stop UniFairy_x64' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /im AppMarket.exe' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c sc stop driver' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c sc stop venbp' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /im Gameloop.exe' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /im AndroidEmulatorEx.exe' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall firewall delete rule name = port' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c sc delete driver' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /im AndroidEmulator.exe' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c sc delete venbp' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM ProjectTitan.exe' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall firewall delete rule name=ven' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall firewall delete rule name = ip' (with hidden window)