Technical Information
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'BraveCrashHandler' = '%ALLUSERSPROFILE%\BraveCrashHandler.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'BraveCrashHandler' = '%ALLUSERSPROFILE%\BraveCrashHandler.exe'
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'BraveCrashHandler' = '%HOMEPATH%\Embedit.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'BraveCrashHandler' = '%HOMEPATH%\Embedit.exe'
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'GoogleCrashHandler' = '%APPDATA%\GoogleCrashHandler.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'GoogleCrashHandler' = '%APPDATA%\GoogleCrashHandler.exe'
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'GoogleCrashHandler64' = '%APPDATA%\GoogleCrashHandler64.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'GoogleCrashHandler64' = '%APPDATA%\GoogleCrashHandler64.exe'
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'SheIlExperienceHost' = '%LOCALAPPDATA%\SheIlExperienceHost.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'SheIlExperienceHost' = '%LOCALAPPDATA%\SheIlExperienceHost.exe'
- [HKLM\System\CurrentControlSet\Services\ProgramsCache] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\ProgramsCache] 'ImagePath' = '%ALLUSERSPROFILE%\BraveCrashHandler.exe'
- [HKLM\System\CurrentControlSet\Services\RegeditCache] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\RegeditCache] 'ImagePath' = '%HOMEPATH%\Embedit.exe'
- [HKLM\System\CurrentControlSet\Services\DevAssocMan] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\DevAssocMan] 'ImagePath' = '%APPDATA%\GoogleCrashHandler.exe'
- [HKLM\System\CurrentControlSet\Services\NgcCpmrSvc] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\NgcCpmrSvc] 'ImagePath' = '%APPDATA%\GoogleCrashHandler64.exe'
- [HKLM\System\CurrentControlSet\Services\RemedyProc] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\RemedyProc] 'ImagePath' = '%LOCALAPPDATA%\SheIlExperienceHost.exe'
- 'ProgramsCache' %ALLUSERSPROFILE%\BraveCrashHandler.exe
- 'RegeditCache' %HOMEPATH%\Embedit.exe
- 'DevAssocMan' %APPDATA%\GoogleCrashHandler.exe
- 'NgcCpmrSvc' %APPDATA%\GoogleCrashHandler64.exe
- 'RemedyProc' %LOCALAPPDATA%\SheIlExperienceHost.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -exec bypass -enc YwBoAGMAcAAgADYANQAwADAAMQAKACQAUAByAG8AZwByAGUAcwBzAFAAcgBlAGYAZQByAGUAbgBjAGUAIAA9ACAAJwBTAGkAbABlAG4AdABsAHkAQwBvAG4AdABpAG4AdQBlACcACgAKAFMAZQB0AC0ARQB4AGUAYwB1AHQAaQBvAG4...
- %TEMP%\0q4aa0l7.bat
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\en-us\unattendprovider.dll.mui
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\en-us\transmogprovider.dll.mui
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\en-us\smiprovider.dll.mui
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\en-us\osprovider.dll.mui
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\en-us\msiprovider.dll.mui
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\en-us\logprovider.dll.mui
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\folderprovider.dll
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\en-us\wimprovider.dll.mui
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\en-us\dmiprovider.dll.mui
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\en-us\dismprov.dll.mui
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\en-us\dismcore.dll.mui
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\en-us\compatprovider.dll.mui
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\en-us\cbsprovider.dll.mui
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\dmiprovider.dll
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\en-us\intlprovider.dll.mui
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\en-us\smiprovider.dll.mui
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\intlprovider.dll
- %WINDIR%\security\database\edb.chk
- %WINDIR%\security\database\tmp.edb
- %WINDIR%\security\database\edb.log
- %WINDIR%\security\database\edbres00002.jrs
- %WINDIR%\security\database\edbres00001.jrs
- %WINDIR%\security\database\edbtmp.log
- <Current directory>\secconfig.cfg
- %TEMP%\sce49387.tmp
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\wdscore.dll
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\wimprovider.dll
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\unattendprovider.dll
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\transmogprovider.dll
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\smiprovider.dll
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\osprovider.dll
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\msiprovider.dll
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\dismprov.dll
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\en-us\folderprovider.dll.mui
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\dismhost.exe
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\dismcoreps.dll
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\dismcore.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\en-us\cbsprovider.dll.mui
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\en-us\intlprovider.dll.mui
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\en-us\folderprovider.dll.mui
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\en-us\dmiprovider.dll.mui
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\en-us\dismprov.dll.mui
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\en-us\dismcore.dll.mui
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\en-us\compatprovider.dll.mui
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\dmiprovider.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\en-us\msiprovider.dll.mui
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\dismprov.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\dismhost.exe
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\dismcoreps.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\dismcore.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\compatprovider.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\cbsprovider.dll
- %WINDIR%\security\logs\scesrv.log
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\logprovider.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\en-us\osprovider.dll.mui
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\en-us\unattendprovider.dll.mui
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\en-us\logprovider.dll.mui
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\compatprovider.dll
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\cbsprovider.dll
- %WINDIR%\logs\dism\dism.log
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\wdscore.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\wimprovider.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\unattendprovider.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\transmogprovider.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\smiprovider.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\osprovider.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\msiprovider.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\logprovider.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\intlprovider.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\folderprovider.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\en-us\wimprovider.dll.mui
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\en-us\transmogprovider.dll.mui
- <Current directory>\secedit.sdb
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\cbsprovider.dll
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\dismcoreps.dll
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\dismhost.exe
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\dismprov.dll
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\dmiprovider.dll
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\en-us\cbsprovider.dll.mui
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\en-us\compatprovider.dll.mui
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\en-us\dismcore.dll.mui
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\en-us\dismprov.dll.mui
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\en-us\dmiprovider.dll.mui
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\en-us\folderprovider.dll.mui
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\en-us\intlprovider.dll.mui
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\en-us\logprovider.dll.mui
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\en-us\msiprovider.dll.mui
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\en-us\osprovider.dll.mui
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\en-us\smiprovider.dll.mui
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\en-us\transmogprovider.dll.mui
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\en-us\unattendprovider.dll.mui
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\en-us\wimprovider.dll.mui
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\folderprovider.dll
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\intlprovider.dll
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\logprovider.dll
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\msiprovider.dll
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\osprovider.dll
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\smiprovider.dll
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\transmogprovider.dll
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\unattendprovider.dll
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\wdscore.dll
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\wimprovider.dll
- %TEMP%\sce49387.tmp
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\dismcore.dll
- <Current directory>\secconfig.cfg
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\compatprovider.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\wimprovider.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\compatprovider.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\dismcore.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\dismcoreps.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\dismhost.exe
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\dismprov.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\dmiprovider.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\en-us\cbsprovider.dll.mui
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\en-us\compatprovider.dll.mui
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\en-us\dismcore.dll.mui
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\en-us\dismprov.dll.mui
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\en-us\dmiprovider.dll.mui
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\en-us\folderprovider.dll.mui
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\en-us\intlprovider.dll.mui
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\en-us\logprovider.dll.mui
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\en-us\msiprovider.dll.mui
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\en-us\osprovider.dll.mui
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\en-us\smiprovider.dll.mui
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\en-us\transmogprovider.dll.mui
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\en-us\unattendprovider.dll.mui
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\en-us\wimprovider.dll.mui
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\folderprovider.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\intlprovider.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\logprovider.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\msiprovider.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\osprovider.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\smiprovider.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\transmogprovider.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\unattendprovider.dll
- %TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\wdscore.dll
- %TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\cbsprovider.dll
- %TEMP%\0q4aa0l7.bat
- from %WINDIR%\security\database\edbtmp.log to %WINDIR%\security\database\edb.log
- %WINDIR%\security\database\edbtmp.log
- '%TEMP%\5653eff9-371b-40c3-b0cf-faa39ab43e2f\dismhost.exe' {28E3ECF3-F1D5-405C-8D77-FB9C4CA0341C}
- '%TEMP%\6fd48a1b-8a84-4f66-82c4-65fd5e1d6ebf\dismhost.exe' {38D27070-5E11-441D-8F8C-10A418349870}
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\0Q4AA0L7.bat" "<Full path to file>" "
- '<SYSTEM32>\chcp.com' 65001
- '<SYSTEM32>\whoami.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -exec bypass -enc YwBoAGMAcAAgADYANQAwADAAMQAKACQAUAByAG8AZwByAGUAcwBzAFAAcgBlAGYAZQByAGUAbgBjAGUAIAA9ACAAJwBTAGkAbABlAG4AdABsAHkAQwBvAG4AdABpAG4AdQBlACcACgAKAFMAZQB0AC0ARQB4AGUAYwB1AHQAaQBvAG4...
- '<SYSTEM32>\dism.exe' /online /enable-feature /featurename:Microsoft-Windows-Subsystem-Linux /all /norestart
- '<SYSTEM32>\dism.exe' /online /enable-feature /featurename:VirtualMachinePlatform /all /norestart
- '<SYSTEM32>\powercfg.exe' /list
- '<SYSTEM32>\powercfg.exe' /s
- '<SYSTEM32>\secedit.exe' /export /cfg secconfig.cfg
- '<SYSTEM32>\secedit.exe' /configure /db secedit.sdb /cfg secconfig.cfg /areas USER_RIGHTS
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\0Q4AA0L7.bat" "<Full path to file>" "' (with hidden window)