Technical Information
- [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] 'avpui2' = '"C:\changan_mark\avpu1.exe"'
- %TEMP%\rarsfx0\avpui1.vbe
- %TEMP%\rarsfx0\avpu1.exe
- %TEMP%\rarsfx0\信息安全警示.txt
- %TEMP%\rarsfx0\avpui1.bat
- %TEMP%\rarsfx0\avpui1.reg
- C:\changan_mark\avpu1.exe
- %TEMP%\rarsfx0\avpu1.exe
- %TEMP%\rarsfx0\avpui1.bat
- %TEMP%\rarsfx0\avpui1.reg
- %TEMP%\rarsfx0\avpui1.vbe
- %TEMP%\rarsfx0\信息安全警示.txt
- ClassName: 'EDIT' WindowName: ''
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\RarSFX0\avpui1.vbe"
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\RarSFX0\avpui1.bat" /start"
- '%WINDIR%\syswow64\xcopy.exe' /y avpu1.exe c:\changan_mark\
- '%WINDIR%\syswow64\xcopy.exe' /y ╨┼╧ÐÑ░▓╚ÐÐ ╛л╩╛.txt c:\changan_mark\
- '%WINDIR%\syswow64\attrib.exe' +h +r c:\changan_mark
- '%WINDIR%\syswow64\reg.exe' import avpui1.reg /reg:64
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\RarSFX0\avpui1.bat" /start"' (with hidden window)