Technical Information
- [HKLM\Software\Classes\.exe] '' = 'exefile'
- [HKLM\Software\Classes\exefile\shell\open\command] '' = '"%1" %*'
- [HKLM\Software\Classes\.bat] '' = 'batfile'
- [HKLM\Software\Classes\batfile\shell\open\command] '' = '"%1" %*'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'GrpConv' = 'grpconv -o'
- %TEMP%\rarsfx0\wl.txt
- %TEMP%\rarsfx0\prep.bat
- %TEMP%\rarsfx0\rkill.bat
- %TEMP%\rarsfx0\s.inf
- %TEMP%\rarsfx0\procs\iexplore.com
- %TEMP%\rarsfx0\h\explorer.exe
- %TEMP%\rarsfx0\procs\explorer.exe
- %TEMP%\rarsfx0\h\iexplore.exe
- %TEMP%\rarsfx0\nird\iexplore.exe
- %TEMP%\rarsfx0\procs\iexplore.exe
- %TEMP%\rarsfx0\nircmd.exe
- %TEMP%\rarsfx0\nircmdc.exe
- %TEMP%\rarsfx0\pev.exe
- %TEMP%\rarsfx0\proxycheck.exe
- %TEMP%\rarsfx0\sed.exe
- %TEMP%\rarsfx0\swreg.exe
- %TEMP%\rarsfx0\userinit.exe
- %TEMP%\rarsfx0\winlogon.exe
- %TEMP%\rarsfx0\extra.dat
- %TEMP%\rarsfx0\procs\proc.dat
- %TEMP%\rarsfx0\serv.dat
- %TEMP%\rarsfx0\rkill.reg
- %TEMP%\rarsfx0\sh.vbs
- %TEMP%\rarsfx0\nircmd.chm
- %TEMP%\rks1.log
- %TEMP%\rarsfx0\ncmd.cfxxe
- %TEMP%\rkill.log
- %LOCALAPPDATA%\microsoft\windows\explorer\explorerstartuplog_runonce.etl
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\rarsfx0\h\explorer.exe' procs\explorer.exe RIMPORT rkill.reg
- '%TEMP%\rarsfx0\procs\explorer.exe' RIMPORT rkill.reg
- '%TEMP%\rarsfx0\h\iexplore.exe' procs\iexplore.exe RIMPORT rkill.reg
- '%TEMP%\rarsfx0\procs\iexplore.exe' RIMPORT rkill.reg
- '%TEMP%\rarsfx0\procs\iexplore.com' RIMPORT rkill.reg
- '%TEMP%\rarsfx0\userinit.exe' shexec install s.inf
- '%TEMP%\rarsfx0\h\explorer.exe' procs\explorer.exe plist %TEMP%\rks1.log
- '%TEMP%\rarsfx0\procs\explorer.exe' plist %TEMP%\rks1.log
- '%TEMP%\rarsfx0\h\iexplore.exe' procs\iexplore.exe plist %TEMP%\rks1.log
- '%TEMP%\rarsfx0\procs\iexplore.exe' plist %TEMP%\rks1.log
- '%TEMP%\rarsfx0\h\iexplore.exe' nird\iexplore.exe sysrefresh
- '%TEMP%\rarsfx0\nird\iexplore.exe' sysrefresh
- '%TEMP%\rarsfx0\h\explorer.exe' procs\explorer.exe -loadline"extra.dat" and not "<Full path to file>"
- '%TEMP%\rarsfx0\procs\explorer.exe' -loadline"extra.dat" and not "<Full path to file>"
- '%TEMP%\rarsfx0\h\iexplore.exe' procs\iexplore.exe -loadline"extra.dat" and not "<Full path to file>"
- '%TEMP%\rarsfx0\procs\iexplore.exe' -loadline"extra.dat" and not "<Full path to file>"
- '%TEMP%\rarsfx0\winlogon.exe' shexec install s.inf
- '%TEMP%\rarsfx0\nird\iexplore.exe' shexec install s.inf
- '%TEMP%\rarsfx0\nird\iexplore.exe' win close stitle "Antivirus Suite"
- '%TEMP%\rarsfx0\nird\iexplore.exe' win close stitle "Smart Security"
- '%TEMP%\rarsfx0\nird\iexplore.exe' win close stitle "Antivirus Soft"
- '%TEMP%\rarsfx0\nird\iexplore.exe' win close stitle "Virus Protection"
- '%TEMP%\rarsfx0\nird\iexplore.exe' win close stitle "Security Tool"
- '%TEMP%\rarsfx0\nird\iexplore.exe' win close stitle "Enterprise Suite"
- '%TEMP%\rarsfx0\nird\iexplore.exe' win close stitle "Security Central"
- '%TEMP%\rarsfx0\nird\iexplore.exe' win close stitle "Security essentials"
- '%TEMP%\rarsfx0\h\iexplore.exe' sv.vbs
- '%TEMP%\rarsfx0\h\explorer.exe' procs\explorer.exe -k gog.exe
- '%TEMP%\rarsfx0\procs\explorer.exe' -k gog.exe
- '%TEMP%\rarsfx0\h\explorer.exe' procs\explorer.exe -k hotfix.exe
- '%TEMP%\rarsfx0\procs\explorer.exe' -k hotfix.exe
- '%TEMP%\rarsfx0\h\iexplore.exe' procs\iexplore.exe -k "%HOMEPATH%\local settings\application data\*.exe"
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k "%HOMEPATH%\local settings\application data\*.exe"
- '%TEMP%\rarsfx0\h\iexplore.exe' procs\iexplore.exe -k "C:\NetworkControl\*.exe"
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k "C:\NetworkControl\*.exe"
- '%TEMP%\rarsfx0\h\iexplore.exe' procs\iexplore.exe -k "%TEMP%\*" and not "<Full path to file>"
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k "%TEMP%\*" and not "<Full path to file>"
- '%TEMP%\rarsfx0\h\iexplore.exe' procs\iexplore.exe -k *tssd.exe
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k *tssd.exe
- '%TEMP%\rarsfx0\h\iexplore.exe' procs\iexplore.exe -k winlogon32.exe
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k winlogon32.exe
- '%TEMP%\rarsfx0\h\iexplore.exe' procs\iexplore.exe -k smss32.exe
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k smss32.exe
- '%TEMP%\rarsfx0\h\iexplore.exe' procs\iexplore.exe -k restore.exe
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k restore.exe
- '%TEMP%\rarsfx0\h\iexplore.exe' procs\iexplore.exe -k "%ALLUSERSPROFILE%\*"
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k "%ALLUSERSPROFILE%\*"
- '%TEMP%\rarsfx0\h\iexplore.exe' procs\iexplore.exe -k "ALLUSE~1\*"
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k "ALLUSE~1\*"
- '%TEMP%\rarsfx0\h\iexplore.exe' procs\iexplore.exe -k "%HOMEPATH%\*" and not "<Full path to file>"
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k "%HOMEPATH%\*" and not "<Full path to file>"
- '%TEMP%\rarsfx0\h\iexplore.exe' procs\iexplore.exe -k antispyshield.exe
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k antispyshield.exe
- '%TEMP%\rarsfx0\h\iexplore.exe' procs\iexplore.exe -k * -preg#\\[0-9]+\.exe$#
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k * -preg#\\[0-9]+\.exe$#
- '%TEMP%\rarsfx0\h\iexplore.exe' procs\iexplore.exe -k *sysguard.exe
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k *sysguard.exe
- '%TEMP%\rarsfx0\h\iexplore.exe' procs\iexplore.exe -k *sftav.exe
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k *sftav.exe
- '%TEMP%\rarsfx0\h\iexplore.exe' procs\iexplore.exe -k *onin.exe
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k *onin.exe
- '%TEMP%\rarsfx0\h\iexplore.exe' procs\iexplore.exe -k "antivirus plus*"
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k "antivirus plus*"
- '%TEMP%\rarsfx0\h\iexplore.exe' procs\iexplore.exe -k :\%ProgramFiles(x86)%\AntiVirus Plus\*.exe
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k :\%ProgramFiles(x86)%\AntiVirus Plus\*.exe
- '%TEMP%\rarsfx0\h\iexplore.exe' procs\iexplore.exe -k "*.tmp.exe"
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k "*.tmp.exe"
- '%TEMP%\rarsfx0\h\iexplore.exe' prep.bat
- '%TEMP%\rarsfx0\h\iexplore.exe' procs\iexplore.exe
- '%TEMP%\rarsfx0\procs\iexplore.exe'
- '%TEMP%\rarsfx0\nircmd.exe' WAIT 35000
- '%WINDIR%\syswow64\infdefaultinstall.exe' "%TEMP%\RarSFX0\s.inf"
- '%WINDIR%\syswow64\runonce.exe' -r
- '%WINDIR%\syswow64\grpconv.exe' -o
- '%WINDIR%\syswow64\cmd.exe' /c prep.bat
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\RarSFX0\rkill.bat" "
- '%TEMP%\rarsfx0\procs\explorer.exe' RIMPORT rkill.reg' (with hidden window)
- '%TEMP%\rarsfx0\procs\iexplore.exe' RIMPORT rkill.reg' (with hidden window)
- '%TEMP%\rarsfx0\procs\explorer.exe' plist %TEMP%\rks1.log' (with hidden window)
- '%TEMP%\rarsfx0\procs\iexplore.exe' plist %TEMP%\rks1.log' (with hidden window)
- '%TEMP%\rarsfx0\nird\iexplore.exe' sysrefresh' (with hidden window)
- '%TEMP%\rarsfx0\procs\explorer.exe' -loadline"extra.dat" and not "<Full path to file>"' (with hidden window)
- '%TEMP%\rarsfx0\procs\iexplore.exe' -loadline"extra.dat" and not "<Full path to file>"' (with hidden window)
- '%TEMP%\rarsfx0\procs\explorer.exe' -k gog.exe' (with hidden window)
- '%TEMP%\rarsfx0\procs\explorer.exe' -k hotfix.exe' (with hidden window)
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k "%HOMEPATH%\local settings\application data\*.exe"' (with hidden window)
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k "C:\NetworkControl\*.exe"' (with hidden window)
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k "%TEMP%\*" and not "<Full path to file>"' (with hidden window)
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k *tssd.exe' (with hidden window)
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k winlogon32.exe' (with hidden window)
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k smss32.exe' (with hidden window)
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k restore.exe' (with hidden window)
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k "%ALLUSERSPROFILE%\*"' (with hidden window)
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k "ALLUSE~1\*"' (with hidden window)
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k "%HOMEPATH%\*" and not "<Full path to file>"' (with hidden window)
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k antispyshield.exe' (with hidden window)
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k * -preg#\\[0-9]+\.exe$#' (with hidden window)
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k *sysguard.exe' (with hidden window)
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k *sftav.exe' (with hidden window)
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k *onin.exe' (with hidden window)
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k "antivirus plus*"' (with hidden window)
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k :\%ProgramFiles(x86)%\AntiVirus Plus\*.exe' (with hidden window)
- '%TEMP%\rarsfx0\procs\iexplore.exe' -k "*.tmp.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c prep.bat' (with hidden window)
- '%TEMP%\rarsfx0\procs\iexplore.exe' ' (with hidden window)