Technical Information
- %ProgramFiles%\internet explorer\en-us\dwm.exe
- %ProgramFiles%\internet explorer\en-us\6cb0b6c459d5d3
- %ProgramFiles%\microsoft sync framework\v1.0\runtime\x64\resources\1033\wudfhost.exe
- %ProgramFiles%\microsoft sync framework\v1.0\runtime\x64\resources\1033\480b7989c529f6
- %ProgramFiles%\microsoft analysis services\as oledb\10\cartridges\wudfhost.exe
- %ProgramFiles%\microsoft analysis services\as oledb\10\cartridges\480b7989c529f6
- %ProgramFiles%\dvd maker\en-us\rundll32.exe
- %ProgramFiles%\dvd maker\en-us\3d4d5fa006b533
- C:\recovery\fc7d0508-3f8d-11ed-bf82-c9aa0b5639b5\sppsvc.exe
- C:\recovery\fc7d0508-3f8d-11ed-bf82-c9aa0b5639b5\0a1fd5f707cd16
- %TEMP%\8qvbkjgjar
- %TEMP%\sqdkbbjurd.bat
- nul
- %TEMP%\8qvbkjgjar
- '89.##5.84.52':80
- http://89.##5.84.52/4Async/windows/PacketVideo_/GeoPollphp/40/ProtecttrackDownloads/Wordpress4Packet/linux7/protect/ApiprotectBaseWp/temporary8asyncAuth/EternalphpPacketGeoUpdateFlowerdownloads...
- 'C:\recovery\fc7d0508-3f8d-11ed-bf82-c9aa0b5639b5\sppsvc.exe'
- '%WINDIR%\syswow64\cmd.exe' /C "%TEMP%\sqdKbbJurD.bat"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C "%TEMP%\sqdKbbJurD.bat"
- '%WINDIR%\syswow64\chcp.com' 65001
- '%WINDIR%\syswow64\ping.exe' -n 10 localhost