Technical Information
- <SYSTEM32>\tasks\taskdirfortaskcreate\taskfortaskcreate
- libmfxsw32.exe
- %APPDATA%\mxmetamux\libmfxsw32.exe
- from <Full path to file> to %APPDATA%\mxmetamux\libmfxsw32.exe
- '%WINDIR%\syswow64\cmd.exe' /c icacls "%APPDATA%\Mxmetamux" /inheritance:e /deny "*S-1-1-0:(R,REA,RA,RD)" & icacls "%APPDATA%\Mxmetamux" /inheritance:e /deny "*S-1-5-7:(R,REA,RA,RD)" & icacls "%APPDATA%\Mxmetamux" /inheri...' (with hidden window)
- '%APPDATA%\mxmetamux\libmfxsw32.exe' ' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c icacls "%APPDATA%\Mxmetamux" /inheritance:e /deny "*S-1-1-0:(R,REA,RA,RD)" & icacls "%APPDATA%\Mxmetamux" /inheritance:e /deny "*S-1-5-7:(R,REA,RA,RD)" & icacls "%APPDATA%\Mxmetamux" /inheri...
- '<SYSTEM32>\taskeng.exe' {1C36594F-52D2-4823-A701-9CAEF258EBC2} S-1-5-21-1960123792-2022915161-3775307078-1001:wvesmzu\user:Interactive:[1]
- '%WINDIR%\syswow64\icacls.exe' "%APPDATA%\Mxmetamux" /inheritance:e /deny "*S-1-1-0:(R,REA,RA,RD)"
- '%WINDIR%\syswow64\icacls.exe' "%APPDATA%\Mxmetamux" /inheritance:e /deny "*S-1-5-7:(R,REA,RA,RD)"
- '%WINDIR%\syswow64\icacls.exe' "%APPDATA%\Mxmetamux" /inheritance:e /deny "user:(R,REA,RA,RD)"