Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\--] 'ImagePath' = '<Full path to file> /wl 1'
- '%TEMP%\nsd3.tmp\ns9.tmp' sc delete --
- '%TEMP%\nsd3.tmp\ns5.tmp' net start --
- '%TEMP%\nsd3.tmp\ns4.tmp' sc create -- binPath= ""<Full path to file>" /wl 1"
- '<SYSTEM32>\net1.exe' start --
- '<SYSTEM32>\sc.exe' delete --
- '<SYSTEM32>\sc.exe' create -- binPath= ""<Full path to file>" /wl 1"
- '<SYSTEM32>\net.exe' start --
- %WINDIR%\Temp\nsv8.tmp\md5dll.dll
- %WINDIR%\Temp\nsv8.tmp\brh.dat
- %WINDIR%\Temp\nsv8.tmp\brh.dll
- %TEMP%\nss2.tmp
- %WINDIR%\Temp\nsf7.tmp
- %WINDIR%\Temp\nsv8.tmp\System.dll
- %WINDIR%\Temp\nsv8.tmp\md5dll.dll
- %WINDIR%\Temp\nsv8.tmp\System.dll
- %TEMP%\nsd3.tmp\ns5.tmp
- %TEMP%\nsd3.tmp\ns4.tmp
- %WINDIR%\Temp\nsv8.tmp\brh.dat
- %WINDIR%\Temp\nsv8.tmp\brh.dll