Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'windows startup' = '<Full path to virus>'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DoNotAllowExceptions' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- <SYSTEM32>\taskkill.exe /f /im egui.EXE
- <SYSTEM32>\taskkill.exe /f /im ekrn.EXE
- <SYSTEM32>\taskkill.exe /f /mi aVP.exe
- <SYSTEM32>\netsh.exe firewall set opmode disable
- <SYSTEM32>\taskkill.exe /f /mi NOD32krn.exe
- <SYSTEM32>\taskkill.exe /f /mi NOD32KUI.EXE
- ekrn.exe
- <Full path to virus>
- ClassName: 'Indicator' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'SysListView32' WindowName: ''
- ClassName: '' WindowName: 'Windows Task Manager'
- ClassName: '#32770' WindowName: ''