Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\FltOkoMgr] 'Start' = '00000002'
- <Full path to virus>.exe -okosurprise
- <SYSTEM32>\sc.exe CreATe "FltOkoMgr" tyPE= share start= auto binPaTh= "<SYSTEM32>\svchost.exe -k meetsvc" DisplayName= "Versions Pluggable VMware Class PCI Card Taskbar App extensions a"
- <SYSTEM32>\netsh.exe fIrEwaLl aDD pOrToPEnIng tcP 8085 "VMware FilterPort" eNABLe
- <SYSTEM32>\reg.exe adD "hkLm\sYsTEm\CuRrenTcoNtRoLSeT\seRvIcES\FltOkoMgr" /v FailureActions /t rEG_BInaRY /d 00000000000000000000000003000000140000000100000060EA00000100000060EA00000100000060EA0000 /f
- <SYSTEM32>\reg.exe adD "hkLm\sYsTEm\CuRrenTcoNtRoLSeT\seRvIcES\FltOkoMgr\Parameters" /v ServiceDll /t ReG_EXpaND_Sz /d "<SYSTEM32>\btw_oko.dll" /f
- <SYSTEM32>\cmd.exe /c "%TEMP%\nlokobmove.bat"
- <SYSTEM32>\cmd.exe /c ""<Full path to virus>.exe" -okosurprise > "%TEMP%\nlokobmove.bat""
- <SYSTEM32>\netsh.exe FIReWAlL Add allOweDPrOgrAm naMe="VMware Update Service" prOGram="<SYSTEM32>\svchost.exe" mode=ENABLE
- <SYSTEM32>\reg.exe aDd "hklm\SOFTWARE\Microsoft\Internet Explorer\Main" /v TP /t ReG_Sz /d "1000" /f
- <DRIVERS>\klifoko.sys
- %TEMP%\nlokobmove.bat
- <Full path to virus>.exe
- <SYSTEM32>\btw_oko.dll
- 'localhost':8085