Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'TEXT' = '%USERNAME%'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Microsoft Word' = '%PROGRAM_FILES%\repair.exe'
- '<SYSTEM32>\net1.exe' user QQ 2475539188 @ten9 /add
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\cmd.exe' /c %TEMP%\29447.tmp.bat
- '<SYSTEM32>\net1.exe' user %USERNAME% /active:no
- %TEMP%\29447.tmp.bat
- %PROGRAM_FILES%\repair.exe
- <SYSTEM32>\PerfStringBackup.TMP
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini