Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\Windows File Server] 'Start' = '00000002'
- %WINDIR%\wfs.exe
- <SYSTEM32>\dumprep.exe 3224 -dm 7 7 %TEMP%\WERdff6.dir00\mmc.exe.hdmp 16325836412027084
- <SYSTEM32>\dumprep.exe 3160 -dm 7 7 %TEMP%\WERb40c.dir00\mmc.exe.hdmp 16325836412027084
- <SYSTEM32>\dumprep.exe 3284 -dm 7 7 %TEMP%\WERf097.dir00\mmc.exe.mdmp 16325836412027072
- <SYSTEM32>\dumprep.exe 3336 -dm 7 7 %TEMP%\WER2907.dir00\mmc.exe.mdmp 16325836412027072
- <SYSTEM32>\dumprep.exe 3284 -dm 7 7 %TEMP%\WERf097.dir00\mmc.exe.hdmp 16325836412027084
- <SYSTEM32>\dumprep.exe 3052 -dm 7 7 %TEMP%\WER54c4.dir00\mmc.exe.hdmp 16325836412027084
- <SYSTEM32>\dumprep.exe 3116 -dm 7 7 %TEMP%\WER8558.dir00\mmc.exe.mdmp 16325836412027072
- <SYSTEM32>\dumprep.exe 3116 -dm 7 7 %TEMP%\WER8558.dir00\mmc.exe.hdmp 16325836412027084
- <SYSTEM32>\dumprep.exe 3224 -dm 7 7 %TEMP%\WERdff6.dir00\mmc.exe.mdmp 16325836412027072
- <SYSTEM32>\dumprep.exe 3160 -dm 7 7 %TEMP%\WERb40c.dir00\mmc.exe.mdmp 16325836412027072
- <SYSTEM32>\dumprep.exe 3336 -dm 7 7 %TEMP%\WER2907.dir00\mmc.exe.hdmp 16325836412027084
- <SYSTEM32>\dumprep.exe 3496 -dm 7 7 %TEMP%\WER94e6.dir00\mmc.exe.hdmp 16325836412027084
- <SYSTEM32>\dumprep.exe 3556 -dm 7 7 %TEMP%\WERddb8.dir00\mmc.exe.mdmp 16325836412027072
- <SYSTEM32>\dumprep.exe 3588 -dm 7 7 %TEMP%\WERfea2.dir00\mmc.exe.mdmp 16325836412027072
- <SYSTEM32>\dumprep.exe 3720 -dm 7 7 %TEMP%\WER4c64.dir00\mmc.exe.mdmp 16325836412027080
- <SYSTEM32>\dumprep.exe 3588 -dm 7 7 %TEMP%\WERfea2.dir00\mmc.exe.hdmp 16325836412027084
- <SYSTEM32>\dumprep.exe 3448 -dm 7 7 %TEMP%\WER8842.dir00\mmc.exe.mdmp 16325836412027072
- <SYSTEM32>\dumprep.exe 3404 -dm 7 7 %TEMP%\WER454e.dir00\mmc.exe.mdmp 16325836412027072
- <SYSTEM32>\dumprep.exe 3404 -dm 7 7 %TEMP%\WER454e.dir00\mmc.exe.hdmp 16325836412027084
- <SYSTEM32>\dumprep.exe 3448 -dm 7 7 %TEMP%\WER8842.dir00\mmc.exe.hdmp 16325836412027084
- <SYSTEM32>\dumprep.exe 3496 -dm 7 7 %TEMP%\WER94e6.dir00\mmc.exe.mdmp 16325836412027072
- <SYSTEM32>\dumprep.exe 2988 -dm 7 7 %TEMP%\WER317b.dir00\mmc.exe.hdmp 16325836412027084
- <SYSTEM32>\dumprep.exe 2676 -dm 7 7 %TEMP%\WER162c.dir00\mmc.exe.hdmp 16325836412027084
- <SYSTEM32>\dumprep.exe 2676 -dm 7 7 %TEMP%\WER162c.dir00\mmc.exe.mdmp 16325836412027072
- <SYSTEM32>\dumprep.exe 2748 -dm 7 7 %TEMP%\WER4c7f.dir00\mmc.exe.mdmp 16325836412027072
- <SYSTEM32>\dumprep.exe 2804 -dm 7 7 %TEMP%\WER668f.dir00\mmc.exe.mdmp 16325836412027072
- <SYSTEM32>\dumprep.exe 2748 -dm 7 7 %TEMP%\WER4c7f.dir00\mmc.exe.hdmp 16325836412027084
- <SYSTEM32>\cmd.exe /c %WINDIR%\SxingDel.bat
- <SYSTEM32>\mmc.exe
- <SYSTEM32>\dumprep.exe 2532 -dm 7 7 %TEMP%\WEReb2d.dir00\mmc.exe.mdmp 16325836412027072
- <SYSTEM32>\rundll32.exe <SYSTEM32>\sysdm.cpl,NoExecuteProcessException <SYSTEM32>\mmc.exe
- <SYSTEM32>\dumprep.exe 2532 -dm 7 7 %TEMP%\WEReb2d.dir00\mmc.exe.hdmp 16325836412027092
- <SYSTEM32>\dumprep.exe 2804 -dm 7 7 %TEMP%\WER668f.dir00\mmc.exe.hdmp 16325836412027084
- <SYSTEM32>\dumprep.exe 2916 -dm 7 7 %TEMP%\WERe77f.dir00\mmc.exe.hdmp 16325836412027084
- <SYSTEM32>\dumprep.exe 2956 -dm 7 7 %TEMP%\WER2ba7.dir00\mmc.exe.mdmp 16325836412027072
- <SYSTEM32>\dumprep.exe 2988 -dm 7 7 %TEMP%\WER317b.dir00\mmc.exe.mdmp 16325836412027072
- <SYSTEM32>\dumprep.exe 3052 -dm 7 7 %TEMP%\WER54c4.dir00\mmc.exe.mdmp 16325836412027072
- <SYSTEM32>\dumprep.exe 2956 -dm 7 7 %TEMP%\WER2ba7.dir00\mmc.exe.hdmp 16325836412027084
- <SYSTEM32>\dumprep.exe 2880 -dm 7 7 %TEMP%\WERca12.dir00\mmc.exe.mdmp 16325836412027072
- <SYSTEM32>\dumprep.exe 2856 -dm 7 7 %TEMP%\WER9865.dir00\mmc.exe.mdmp 16325836412027072
- <SYSTEM32>\dumprep.exe 2856 -dm 7 7 %TEMP%\WER9865.dir00\mmc.exe.hdmp 16325836412027084
- <SYSTEM32>\dumprep.exe 2880 -dm 7 7 %TEMP%\WERca12.dir00\mmc.exe.hdmp 16325836412027084
- <SYSTEM32>\dumprep.exe 2916 -dm 7 7 %TEMP%\WERe77f.dir00\mmc.exe.mdmp 16325836412027072
- <SYSTEM32>\mmc.exe
- %TEMP%\WERb40c.dir00\appcompat.txt
- %TEMP%\WERb40c.dir00\manifest.txt
- %TEMP%\WERf097.dir00\mmc.exe.mdmp
- %TEMP%\WERb40c.dir00\mmc.exe.hdmp
- %TEMP%\WERdff6.dir00\mmc.exe.hdmp
- %TEMP%\WER2907.dir00\mmc.exe.mdmp
- %TEMP%\WERf097.dir00\appcompat.txt
- %TEMP%\WERf097.dir00\mmc.exe.hdmp
- %TEMP%\WERdff6.dir00\appcompat.txt
- %TEMP%\WERdff6.dir00\manifest.txt
- %TEMP%\WER54c4.dir00\appcompat.txt
- %TEMP%\WER8558.dir00\mmc.exe.hdmp
- %TEMP%\WER54c4.dir00\mmc.exe.hdmp
- %TEMP%\WER2ba7.dir00\manifest.txt
- %TEMP%\WER317b.dir00\manifest.txt
- %TEMP%\WER8558.dir00\appcompat.txt
- %TEMP%\WER8558.dir00\manifest.txt
- %TEMP%\WERdff6.dir00\mmc.exe.mdmp
- %TEMP%\WERb40c.dir00\mmc.exe.mdmp
- %TEMP%\WER54c4.dir00\manifest.txt
- %TEMP%\WERf097.dir00\manifest.txt
- %TEMP%\WERfea2.dir00\mmc.exe.mdmp
- %TEMP%\WER94e6.dir00\mmc.exe.hdmp
- %TEMP%\WER8842.dir00\manifest.txt
- %TEMP%\WER8842.dir00\appcompat.txt
- %TEMP%\WERddb8.dir00\mmc.exe.mdmp
- %TEMP%\WERfea2.dir00\appcompat.txt
- %TEMP%\WERfea2.dir00\manifest.txt
- %TEMP%\WERfea2.dir00\mmc.exe.hdmp
- %TEMP%\WER94e6.dir00\appcompat.txt
- %TEMP%\WER94e6.dir00\manifest.txt
- %TEMP%\WER8842.dir00\mmc.exe.mdmp
- %TEMP%\WER2907.dir00\manifest.txt
- %TEMP%\WER2907.dir00\appcompat.txt
- %TEMP%\WER2907.dir00\mmc.exe.hdmp
- %TEMP%\WER454e.dir00\mmc.exe.mdmp
- %TEMP%\WER454e.dir00\appcompat.txt
- %TEMP%\WER454e.dir00\manifest.txt
- %TEMP%\WER8842.dir00\mmc.exe.hdmp
- %TEMP%\WER454e.dir00\mmc.exe.hdmp
- %TEMP%\WER94e6.dir00\mmc.exe.mdmp
- %TEMP%\WER4c7f.dir00\mmc.exe.mdmp
- %TEMP%\WER4c7f.dir00\mmc.exe.hdmp
- %TEMP%\WER162c.dir00\manifest.txt
- %TEMP%\WER162c.dir00\mmc.exe.hdmp
- %TEMP%\WER162c.dir00\appcompat.txt
- %TEMP%\WER668f.dir00\mmc.exe.hdmp
- %TEMP%\WER668f.dir00\appcompat.txt
- %TEMP%\WER668f.dir00\mmc.exe.mdmp
- %TEMP%\WER4c7f.dir00\appcompat.txt
- %TEMP%\WER4c7f.dir00\manifest.txt
- <SYSTEM32>\_wfs.exe
- %WINDIR%\SxingDel.bat
- C:\wfs.exe
- %WINDIR%\wfs.exe
- C:\AutoRun.inf
- %TEMP%\WEReb2d.dir00\manifest.txt
- %TEMP%\WER162c.dir00\mmc.exe.mdmp
- %TEMP%\WEReb2d.dir00\appcompat.txt
- %TEMP%\WEReb2d.dir00\mmc.exe.mdmp
- %TEMP%\WEReb2d.dir00\mmc.exe.hdmp
- %TEMP%\WER668f.dir00\manifest.txt
- %TEMP%\WER2ba7.dir00\mmc.exe.hdmp
- %TEMP%\WERca12.dir00\manifest.txt
- %TEMP%\WERca12.dir00\appcompat.txt
- %TEMP%\WERe77f.dir00\manifest.txt
- %TEMP%\WER317b.dir00\mmc.exe.mdmp
- %TEMP%\WER317b.dir00\appcompat.txt
- %TEMP%\WER2ba7.dir00\appcompat.txt
- %TEMP%\WER8558.dir00\mmc.exe.mdmp
- %TEMP%\WER54c4.dir00\mmc.exe.mdmp
- %TEMP%\WER317b.dir00\mmc.exe.hdmp
- %TEMP%\WERe77f.dir00\mmc.exe.mdmp
- %TEMP%\WER9865.dir00\appcompat.txt
- %TEMP%\WER9865.dir00\mmc.exe.hdmp
- %TEMP%\WER9865.dir00\mmc.exe.mdmp
- %TEMP%\WERca12.dir00\mmc.exe.mdmp
- %TEMP%\WERe77f.dir00\mmc.exe.hdmp
- %TEMP%\WERe77f.dir00\appcompat.txt
- %TEMP%\WER2ba7.dir00\mmc.exe.mdmp
- %TEMP%\WERca12.dir00\mmc.exe.hdmp
- %TEMP%\WER9865.dir00\manifest.txt
- C:\wfs.exe
- <SYSTEM32>\_wfs.exe
- %WINDIR%\wfs.exe
- C:\AutoRun.inf
- %TEMP%\WER94e6.dir00\appcompat.txt
- %TEMP%\WER94e6.dir00\manifest.txt
- %TEMP%\WER94e6.dir00\mmc.exe.hdmp
- %TEMP%\WER94e6.dir00\mmc.exe.mdmp
- %TEMP%\WER8842.dir00\appcompat.txt
- %TEMP%\WER8842.dir00\manifest.txt
- %TEMP%\WER8842.dir00\mmc.exe.hdmp
- %TEMP%\WER8842.dir00\mmc.exe.mdmp
- 'qq##.vicp.net':200
- DNS ASK qq##.vicp.net
- ClassName: 'TReserver0919' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_WINHELP' WindowName: ''