Technical Information
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'BraveCrashHandler' = '%ALLUSERSPROFILE%\BraveCrashHandler.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'BraveCrashHandler' = '%ALLUSERSPROFILE%\BraveCrashHandler.exe'
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'BraveCrashHandler' = '%HOMEPATH%\Embedit.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'BraveCrashHandler' = '%HOMEPATH%\Embedit.exe'
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'GoogleCrashHandler' = '%APPDATA%\GoogleCrashHandler.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'GoogleCrashHandler' = '%APPDATA%\GoogleCrashHandler.exe'
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'GoogleCrashHandler64' = '%APPDATA%\GoogleCrashHandler64.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'GoogleCrashHandler64' = '%APPDATA%\GoogleCrashHandler64.exe'
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'SheIlExperienceHost' = '%LOCALAPPDATA%\SheIlExperienceHost.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'SheIlExperienceHost' = '%LOCALAPPDATA%\SheIlExperienceHost.exe'
- [HKLM\System\CurrentControlSet\Services\ProgramsCache] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\ProgramsCache] 'ImagePath' = '%ALLUSERSPROFILE%\BraveCrashHandler.exe'
- [HKLM\System\CurrentControlSet\Services\RegeditCache] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\RegeditCache] 'ImagePath' = '%HOMEPATH%\Embedit.exe'
- [HKLM\System\CurrentControlSet\Services\DevAssocMan] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\DevAssocMan] 'ImagePath' = '%APPDATA%\GoogleCrashHandler.exe'
- [HKLM\System\CurrentControlSet\Services\NgcCpmrSvc] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\NgcCpmrSvc] 'ImagePath' = '%APPDATA%\GoogleCrashHandler64.exe'
- [HKLM\System\CurrentControlSet\Services\RemedyProc] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\RemedyProc] 'ImagePath' = '%LOCALAPPDATA%\SheIlExperienceHost.exe'
- 'ProgramsCache' %ALLUSERSPROFILE%\BraveCrashHandler.exe
- 'RegeditCache' %HOMEPATH%\Embedit.exe
- 'DevAssocMan' %APPDATA%\GoogleCrashHandler.exe
- 'NgcCpmrSvc' %APPDATA%\GoogleCrashHandler64.exe
- 'RemedyProc' %LOCALAPPDATA%\SheIlExperienceHost.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -exec bypass -enc YwBoAGMAcAAgADYANQAwADAAMQAKACQAUAByAG8AZwByAGUAcwBzAFAAcgBlAGYAZQByAGUAbgBjAGUAIAA9ACAAJwBTAGkAbABlAG4AdABsAHkAQwBvAG4AdABpAG4AdQBlACcACgAKAFMAZQB0AC0ARQB4AGUAYwB1AHQAaQBvAG4...
- %TEMP%\0ye1g6wm.bat
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\en-us\unattendprovider.dll.mui
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\en-us\transmogprovider.dll.mui
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\en-us\smiprovider.dll.mui
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\en-us\osprovider.dll.mui
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\en-us\msiprovider.dll.mui
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\en-us\logprovider.dll.mui
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\folderprovider.dll
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\en-us\wimprovider.dll.mui
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\en-us\dmiprovider.dll.mui
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\en-us\dismprov.dll.mui
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\en-us\dismcore.dll.mui
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\en-us\compatprovider.dll.mui
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\en-us\cbsprovider.dll.mui
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\dmiprovider.dll
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\en-us\intlprovider.dll.mui
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\en-us\smiprovider.dll.mui
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\intlprovider.dll
- %WINDIR%\security\database\edb.chk
- %WINDIR%\security\database\tmp.edb
- %WINDIR%\security\database\edb.log
- %WINDIR%\security\database\edbres00002.jrs
- %WINDIR%\security\database\edbres00001.jrs
- %WINDIR%\security\database\edbtmp.log
- <Current directory>\secconfig.cfg
- %TEMP%\sce54672.tmp
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\wdscore.dll
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\wimprovider.dll
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\unattendprovider.dll
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\transmogprovider.dll
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\smiprovider.dll
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\osprovider.dll
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\msiprovider.dll
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\dismprov.dll
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\en-us\folderprovider.dll.mui
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\dismhost.exe
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\dismcoreps.dll
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\dismcore.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\en-us\cbsprovider.dll.mui
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\en-us\intlprovider.dll.mui
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\en-us\folderprovider.dll.mui
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\en-us\dmiprovider.dll.mui
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\en-us\dismprov.dll.mui
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\en-us\dismcore.dll.mui
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\en-us\compatprovider.dll.mui
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\dmiprovider.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\en-us\msiprovider.dll.mui
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\dismprov.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\dismhost.exe
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\dismcoreps.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\dismcore.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\compatprovider.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\cbsprovider.dll
- %WINDIR%\security\logs\scesrv.log
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\logprovider.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\en-us\osprovider.dll.mui
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\en-us\unattendprovider.dll.mui
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\en-us\logprovider.dll.mui
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\compatprovider.dll
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\cbsprovider.dll
- %WINDIR%\logs\dism\dism.log
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\wdscore.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\wimprovider.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\unattendprovider.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\transmogprovider.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\smiprovider.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\osprovider.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\msiprovider.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\logprovider.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\intlprovider.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\folderprovider.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\en-us\wimprovider.dll.mui
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\en-us\transmogprovider.dll.mui
- <Current directory>\secedit.sdb
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\cbsprovider.dll
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\dismcoreps.dll
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\dismhost.exe
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\dismprov.dll
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\dmiprovider.dll
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\en-us\cbsprovider.dll.mui
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\en-us\compatprovider.dll.mui
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\en-us\dismcore.dll.mui
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\en-us\dismprov.dll.mui
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\en-us\dmiprovider.dll.mui
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\en-us\folderprovider.dll.mui
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\en-us\intlprovider.dll.mui
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\en-us\logprovider.dll.mui
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\en-us\msiprovider.dll.mui
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\en-us\osprovider.dll.mui
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\en-us\smiprovider.dll.mui
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\en-us\transmogprovider.dll.mui
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\en-us\unattendprovider.dll.mui
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\en-us\wimprovider.dll.mui
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\folderprovider.dll
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\intlprovider.dll
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\logprovider.dll
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\msiprovider.dll
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\osprovider.dll
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\smiprovider.dll
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\transmogprovider.dll
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\unattendprovider.dll
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\wdscore.dll
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\wimprovider.dll
- %TEMP%\sce54672.tmp
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\dismcore.dll
- <Current directory>\secconfig.cfg
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\compatprovider.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\wimprovider.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\compatprovider.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\dismcore.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\dismcoreps.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\dismhost.exe
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\dismprov.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\dmiprovider.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\en-us\cbsprovider.dll.mui
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\en-us\compatprovider.dll.mui
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\en-us\dismcore.dll.mui
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\en-us\dismprov.dll.mui
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\en-us\dmiprovider.dll.mui
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\en-us\folderprovider.dll.mui
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\en-us\intlprovider.dll.mui
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\en-us\logprovider.dll.mui
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\en-us\msiprovider.dll.mui
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\en-us\osprovider.dll.mui
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\en-us\smiprovider.dll.mui
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\en-us\transmogprovider.dll.mui
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\en-us\unattendprovider.dll.mui
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\en-us\wimprovider.dll.mui
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\folderprovider.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\intlprovider.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\logprovider.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\msiprovider.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\osprovider.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\smiprovider.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\transmogprovider.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\unattendprovider.dll
- %TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\wdscore.dll
- %TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\cbsprovider.dll
- %TEMP%\0ye1g6wm.bat
- from %WINDIR%\security\database\edbtmp.log to %WINDIR%\security\database\edb.log
- %WINDIR%\security\database\edbtmp.log
- '%TEMP%\857c6d16-e1dd-4757-98bd-a5fc988ab0fe\dismhost.exe' {CF74391D-2761-4952-B9B8-9244302A6275}
- '%TEMP%\d9e85fe4-36f4-4946-a450-90f6c2b1ed7b\dismhost.exe' {CD58CC04-FB7E-4CB0-B063-384A5F33110F}
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\0YE1G6WM.bat" "<Full path to file>" "
- '<SYSTEM32>\chcp.com' 65001
- '<SYSTEM32>\whoami.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -exec bypass -enc YwBoAGMAcAAgADYANQAwADAAMQAKACQAUAByAG8AZwByAGUAcwBzAFAAcgBlAGYAZQByAGUAbgBjAGUAIAA9ACAAJwBTAGkAbABlAG4AdABsAHkAQwBvAG4AdABpAG4AdQBlACcACgAKAFMAZQB0AC0ARQB4AGUAYwB1AHQAaQBvAG4...
- '<SYSTEM32>\dism.exe' /online /enable-feature /featurename:Microsoft-Windows-Subsystem-Linux /all /norestart
- '<SYSTEM32>\dism.exe' /online /enable-feature /featurename:VirtualMachinePlatform /all /norestart
- '<SYSTEM32>\powercfg.exe' /list
- '<SYSTEM32>\powercfg.exe' /s
- '<SYSTEM32>\secedit.exe' /export /cfg secconfig.cfg
- '<SYSTEM32>\secedit.exe' /configure /db secedit.sdb /cfg secconfig.cfg /areas USER_RIGHTS
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\0YE1G6WM.bat" "<Full path to file>" "' (with hidden window)