Technical Information
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe,"%APPDATA%\Xvwkwzjvw\Rbdwsglpx.exe",'
- <SYSTEM32>\notepad.exe
- %APPDATA%\xvwkwzjvw\rbdwsglpx.exe
- %APPDATA%\google\libs\wr64.sys
- 'jr###nace.com':80
- http://jr###nace.com/Owojbhygx_Tiscsllw.png
- DNS ASK st####verflow.com
- DNS ASK jr###nace.com
- '<SYSTEM32>\cmd.exe' /c timeout 45' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c powercfg /x -hibernate-timeout-ac 0 & powercfg /x -hibernate-timeout-dc 0 & powercfg /x -standby-timeout-ac 0 & powercfg /x -standby-timeout-dc 0' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c timeout 45
- '<SYSTEM32>\timeout.exe' 45
- '<SYSTEM32>\cmd.exe' /c powercfg /x -hibernate-timeout-ac 0 & powercfg /x -hibernate-timeout-dc 0 & powercfg /x -standby-timeout-ac 0 & powercfg /x -standby-timeout-dc 0
- '<SYSTEM32>\powercfg.exe' /x -hibernate-timeout-ac 0
- '<SYSTEM32>\powercfg.exe' /x -hibernate-timeout-dc 0
- '<SYSTEM32>\powercfg.exe' /x -standby-timeout-ac 0
- '<SYSTEM32>\powercfg.exe' /x -standby-timeout-dc 0
- '<SYSTEM32>\notepad.exe' zhicacgjhnuj0 6E3sjfZq2rJQaxvLPmXgsBL6xjjYguHWtOpZ+stIdvsjpN5Mqdy4DBfa6KATFfaKtAojfzUwjTQS8LU11cio3B91Dnx64uJpd+yv3ODgmKtlyHUG4wlRe6qD3C4hnccuCyfObt0sQRm3xP0XSv1OFHH30qIKppKf2w90wbt8GGZsj8u4ML7...