Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ShinoBOT' = '"%HOMEPATH%\ShinoBOT.exe"'
- [<HKLM>\System\CurrentControlSet\Services\IKEEXT] 'Start' = '00000002'
- User Account Control (UAC)
- '%WINDIR%\syswow64\netsh.exe' firewall set opmode mode=disable
- '%WINDIR%\syswow64\net.exe' stop wuauserv
- '%WINDIR%\syswow64\net.exe' stop McShield
- %HOMEPATH%\shinobot.exe
- '54.##4.189.77':80
- '%WINDIR%\syswow64\netsh.exe' firewall set opmode mode=disable' (with hidden window)
- '%WINDIR%\syswow64\net.exe' stop wuauserv' (with hidden window)
- '%WINDIR%\syswow64\net.exe' stop McShield' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 0 /f' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 0 /f
- '%WINDIR%\syswow64\net1.exe' stop wuauserv
- '%WINDIR%\syswow64\net1.exe' stop McShield