Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'tetris.vbs' = '\'
- '<SYSTEM32>\findstr.exe' /pid=3148
- '<SYSTEM32>\reg.exe' /FI "IMAGENAME eq TASKMGR.EXE"
- '<SYSTEM32>\ping.exe' /pid=3308
- '<SYSTEM32>\findstr.exe' /pid=3884
- '<SYSTEM32>\findstr.exe' /pid=5256
- '<SYSTEM32>\tasklist.exe' /pid=4188
- '<SYSTEM32>\tasklist.exe' /pid=4248
- '<SYSTEM32>\findstr.exe' /pid=4276
- '<SYSTEM32>\findstr.exe' -n 5 127.0.0.1
- '<SYSTEM32>\tasklist.exe' C:\1.txt
- '<SYSTEM32>\tasklist.exe' /pid=3572
- '<SYSTEM32>\tasklist.exe' /pid=3960
- '<SYSTEM32>\findstr.exe' /FI "IMAGENAME eq explorer.exe"
- '<SYSTEM32>\findstr.exe' /pid=296
- '<SYSTEM32>\ping.exe' /pid=268
- '<SYSTEM32>\findstr.exe' /FI "IMAGENAME eq calc.exe"
- '<SYSTEM32>\ping.exe' /pid=3556
- '<SYSTEM32>\findstr.exe' /pid=5168
- '<SYSTEM32>\findstr.exe' /pid=6116
- '<SYSTEM32>\ping.exe' /pid=5992
- '<SYSTEM32>\tasklist.exe' /pid=6024
- '<SYSTEM32>\tasklist.exe' C:\2.txt
- '<SYSTEM32>\findstr.exe' /pid=1588
- '<SYSTEM32>\tasklist.exe' /pid=6020
- '<SYSTEM32>\findstr.exe' -n 5 localhost
- '<SYSTEM32>\ping.exe' /pid=5996
- '<SYSTEM32>\tasklist.exe' /pid=6032
- '<SYSTEM32>\tasklist.exe' /pid=3828
- '<SYSTEM32>\tasklist.exe' /pid=4404
- '<SYSTEM32>\ping.exe' /pid=4708
- '<SYSTEM32>\findstr.exe' /pid=3560
- '<SYSTEM32>\reg.exe' /pid=3188
- '<SYSTEM32>\tasklist.exe' /pid=5972
- '<SYSTEM32>\findstr.exe' /pid=4860
- '<SYSTEM32>\findstr.exe' /pid=3300
- '<SYSTEM32>\findstr.exe' /pid=4704
- '<SYSTEM32>\tasklist.exe' /pid=4444
- '<SYSTEM32>\ping.exe' /FI "IMAGENAME eq explorer.exe"
- '<SYSTEM32>\ping.exe' /pid=5764
- '<SYSTEM32>\tasklist.exe' /pid=5864
- '<SYSTEM32>\tasklist.exe' /pid=5896
- '<SYSTEM32>\findstr.exe' /pid=2716
- '<SYSTEM32>\findstr.exe' /pid=3588
- '<SYSTEM32>\findstr.exe' /pid=4072
- '<SYSTEM32>\notepad.exe' C:\1.txt
- '<SYSTEM32>\ping.exe' -n 5 127.0.0.1
- '<SYSTEM32>\ping.exe' -n 60 127.0.0.1
- '<SYSTEM32>\cmd.exe' /c ""C:\6.bat" "
- '<SYSTEM32>\ping.exe' -n 25 127.0.0.1
- '<SYSTEM32>\notepad.exe' C:\2.txt
- '<SYSTEM32>\ping.exe' -n 30 127.0.0.1
- '<SYSTEM32>\ping.exe' -n 5 localhost
- '<SYSTEM32>\taskkill.exe' /F /IM explorer.exe
- '<SYSTEM32>\calc.exe'
- '<SYSTEM32>\cmd.exe' /c ""C:\5.bat" "
- '<SYSTEM32>\cmd.exe' /c ""C:\2.bat" "
- '<SYSTEM32>\findstr.exe' PID
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq calc.exe"
- '<SYSTEM32>\wscript.exe' "C:\tetris.vbs"
- '<SYSTEM32>\cmd.exe' /c ""C:\1.bat" "
- '<SYSTEM32>\cmd.exe' /c ""C:\4.bat" "
- '<SYSTEM32>\reg.exe' add hklm\software\microsoft\windows\currentversion\run /v tetris.vbs /d \ /t reg_sz /f
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq explorer.exe"
- '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq TASKMGR.EXE"
- '<SYSTEM32>\cmd.exe' /c ""C:\3.bat" "
- '<SYSTEM32>\reg.exe' /pid=272
- '<SYSTEM32>\taskkill.exe' PID
- '<SYSTEM32>\findstr.exe' /pid=3048
- '<SYSTEM32>\findstr.exe' /pid=2712
- '<SYSTEM32>\ping.exe' /FI "IMAGENAME eq calc.exe"
- '<SYSTEM32>\findstr.exe' /pid=3100
- '<SYSTEM32>\findstr.exe' /FI "IMAGENAME eq TASKMGR.EXE"
- '<SYSTEM32>\findstr.exe' /pid=3524
- '<SYSTEM32>\tasklist.exe' /pid=3700
- '<SYSTEM32>\ping.exe' /pid=3120
- '<SYSTEM32>\ping.exe' /pid=3836
- '<SYSTEM32>\findstr.exe' /pid=204
- '<SYSTEM32>\findstr.exe' C:\1.txt
- '<SYSTEM32>\tasklist.exe' PID
- '<SYSTEM32>\ping.exe' PID
- '<SYSTEM32>\findstr.exe' /pid=2760
- '<SYSTEM32>\tasklist.exe' /pid=3260
- '<SYSTEM32>\reg.exe' /FI "IMAGENAME eq explorer.exe"
- '<SYSTEM32>\tasklist.exe' -n 30 127.0.0.1
- '<SYSTEM32>\findstr.exe' C:\2.txt
- '<SYSTEM32>\ping.exe' /FI "IMAGENAME eq TASKMGR.EXE"
- '<SYSTEM32>\tasklist.exe' /pid=3192
- <SYSTEM32>\reg.exe
- <SYSTEM32>\taskkill.exe
- <SYSTEM32>\ping.exe
- <SYSTEM32>\tasklist.exe
- <SYSTEM32>\findstr.exe
- %WINDIR%\Explorer.EXE
- C:\5.bat
- C:\4.bat
- C:\6.bat
- C:\2.txt
- C:\1.txt
- C:\tetris.vbs
- %TEMP%\sfx.ini
- C:\1.bat
- C:\3.bat
- C:\2.bat
- %TEMP%\sfx.ini
- 'www.as##all.com':80
- 'localhost':1036
- DNS ASK www.pa###racos.es
- DNS ASK www.xn##.com
- DNS ASK www.as##all.com
- DNS ASK www.te###now.com
- ClassName: 'IEFrame' WindowName: '(null)'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: '(null)' WindowName: '(null)'
- ClassName: '' WindowName: '(null)'