Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\NtmsLibSvc] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\NtmsLib] 'Start' = '00000002'
- <SYSTEM32>\dllcache\rdpwd.sys with <SYSTEM32>\dllcache\rdpwd.sys.new
- <DRIVERS>\rdpwd.sys with <DRIVERS>\rdpwd.sys.tmp
- '%TEMP%\~FB1.tmp' 60<Full path to virus>
- '<SYSTEM32>\svchost.exe' -k NtmsLib
- NtEnumerateValueKey, handler: NtmsLib.sys
- NtQueryDirectoryFile, handler: NtmsLib.sys
- NtDeviceIoControlFile, handler: NtmsLib.sys
- NtEnumerateKey, handler: NtmsLib.sys
- %TEMP%\~FB1.tmp
- <SYSTEM32>\NtmsLib\log.ini
- <DRIVERS>\NtmsLib.sys.tmp
- <SYSTEM32>\NtmsLib.dll
- <SYSTEM32>\NtmsLib.dll
- <DRIVERS>\rdpwd.sys
- from <DRIVERS>\rdpwd.sys.new to <DRIVERS>\rdpwd.sys
- from <DRIVERS>\NtmsLib.sys.tmp to <DRIVERS>\NtmsLib.sys