Technical Information
- '%TEMP%\svchost.exe'
- '%TEMP%\sqAqIy.exe' gYSWtv
- '<SYSTEM32>\schtasks.exe' /create /sc minute /mo 1 /tn WindowsUpdategyswtv0x8429525 /tr "C:\ProgramData\gyswtv\hnchRP.vbs" /RL HIGHEST
- '<SYSTEM32>\schtasks.exe' /delete /tn WindowsUpdategyswtv0x8429524
- C:\ProgramData\gyswtv\tGKCfS.txt
- C:\ProgramData\gyswtv\sqAqIy.exe
- %TEMP%\svchost.exe
- <SYSTEM32>\Tasks\WindowsUpdategyswtv0x8429525
- C:\ProgramData\gyswtv\gYSWtv
- C:\ProgramData\gyswtv\hnchRP.vbs
- %TEMP%\aut4663.tmp
- %TEMP%\sqAqIy.exe
- %TEMP%\aut45C6.tmp
- %TEMP%\gYSWtv
- %TEMP%\aut46D1.tmp
- %TEMP%\tGKCfS.txt
- %TEMP%\gYSWtv
- %TEMP%\tGKCfS.txt
- %TEMP%\aut46D1.tmp
- %TEMP%\aut45C6.tmp
- %TEMP%\aut4663.tmp
- from %TEMP%\sqAqIy.exe to %TEMP%\sqAqIy.exe
- '18#.#0.56.24':200
- ClassName: 'Shell_TrayWnd' WindowName: ''