Technical Information
- '<SYSTEM32>\cacls.exe' %TEMP%\ /e /p everyone:f cacls "%WINDIR%" /e /p everyone:f
- '<SYSTEM32>\taskkill.exe' /im 360sd_se.exe /f
- '<SYSTEM32>\sc.exe' config AVP start= disabled
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\a18467stva41a.dll, droqp
- '<SYSTEM32>\taskkill.exe' /im 360sd.exe /f
- '<SYSTEM32>\sc.exe' config rsravmon start= disabled
- '<SYSTEM32>\sc.exe' config ekrn start= disabled
- '<SYSTEM32>\taskkill.exe' /im egui.exe /f
- '<SYSTEM32>\taskkill.exe' /im ekrn.exe /f
- ekrn.exe
- <Auxiliary element>
- %TEMP%\pci1.sys
- <SYSTEM32>\a18467stva41a.dll
- ClassName: '(null)' WindowName: '(null)'