Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '5ce8d7a32ebde5c03cfffed5de8910a2' = '"%APPDATA%\Skila.exe" ..'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '5ce8d7a32ebde5c03cfffed5de8910a2' = '"%APPDATA%\Skila.exe" ..'
- %HOMEPATH%\Start Menu\Programs\Startup\5ce8d7a32ebde5c03cfffed5de8910a2.exe
- %HOMEPATH%\Start Menu\Programs\Startup\1.exe
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%APPDATA%\Skila.exe' = '%APPDATA%\Skila.exe:*:Enabled:Skila.exe'
- '%APPDATA%\Skila.exe'
- '%TEMP%\1.exe'
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%APPDATA%\Skila.exe" "Skila.exe" ENABLE
- %ALLUSERSPROFILE%\Application Data\IsolatedStorage\5AC7BA2F\90424E7E
- %ALLUSERSPROFILE%\Application Data\IsolatedStorage\5AC7BA2F\44538E74
- %ALLUSERSPROFILE%\Application Data\IsolatedStorage\5AC7BA2F\59FD041E
- %ALLUSERSPROFILE%\Application Data\Microsoft\Crypto\RSA\MachineKeys\2c06a5241cb4f9d87cea75ba36e75ff6_23ef5514-3059-436f-a4a7-4cefaab20eb1
- %ALLUSERSPROFILE%\Application Data\Microsoft\Crypto\RSA\MachineKeys\bbc0fb30e96814eb9e925e19c56e4f04_23ef5514-3059-436f-a4a7-4cefaab20eb1
- %APPDATA%\Skila.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\Crypto\RSA\MachineKeys\53539d1181697fe69918c3769d90b6dd_23ef5514-3059-436f-a4a7-4cefaab20eb1
- %TEMP%\aut2.tmp
- %TEMP%\1.exe
- %TEMP%\aut1.tmp
- <SYSTEM32>\Microsoft\Protect\S-1-5-18\Preferred
- <SYSTEM32>\Microsoft\Protect\S-1-5-18\c8f5c69b-521d-4604-905d-06ba7798f8a4
- %ALLUSERSPROFILE%\Application Data\Microsoft\Crypto\RSA\MachineKeys\e715387627d16ef636b63f32fda8fb95_23ef5514-3059-436f-a4a7-4cefaab20eb1
- %ALLUSERSPROFILE%\Application Data\Microsoft\Crypto\RSA\MachineKeys\53539d1181697fe69918c3769d90b6dd_23ef5514-3059-436f-a4a7-4cefaab20eb1
- %ALLUSERSPROFILE%\Application Data\Microsoft\Crypto\RSA\MachineKeys\e715387627d16ef636b63f32fda8fb95_23ef5514-3059-436f-a4a7-4cefaab20eb1
- %TEMP%\aut1.tmp
- %TEMP%\aut2.tmp
- 'ma###.no-ip.org':1177
- DNS ASK ma###.no-ip.org
- ClassName: 'Indicator' WindowName: '(null)'