Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'scrss.exe' = '"%LOCALAPPDATA%\scrss.exe "'
- %LOCALAPPDATA%\ntldr.dll
- %LOCALAPPDATA%\scrss.exe
- %LOCALAPPDATA%\virtualdub.exe
- <Current directory>\syscheck.bat
- '255.255.255.255':1234
- DNS ASK me####era.no-ip.org
- '%LOCALAPPDATA%\scrss.exe'
- '%LOCALAPPDATA%\virtualdub.exe'
- '%WINDIR%\syswow64\cmd.exe' /c syscheck.bat' (with hidden window)
- '%LOCALAPPDATA%\scrss.exe' ' (with hidden window)
- '%LOCALAPPDATA%\virtualdub.exe' ' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c syscheck.bat
- '%WINDIR%\syswow64\cmd.exe' /c REG ADD HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run /V scrss.exe /D "\"%LOCALAPPDATA%\scrss.exe \"" /f
- '%WINDIR%\syswow64\reg.exe' ADD HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run /V scrss.exe /D "\"%LOCALAPPDATA%\scrss.exe \"" /f