Technical Information
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'Microsoft Security' = 'C:\MicrosoftSecurity\MicrosoftCMD.lnk'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Microsoft Security' = 'C:\MicrosoftSecurity\MicrosoftCMD.lnk'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'MicrosoftOffice' = 'C:\MicrosoftSecurity\MicrosoftUpdate.lnk'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Cortana' = 'C:\MicrosoftSecurity\MicrosoftUpdate.lnk'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'HDAudio' = 'C:\MicrosoftSecurity\MicrosoftSecurity.exe /AutoIt3ExecuteScript C:\MicrosoftSecurity\Microsoft.a3x'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'PrintDriver' = 'C:\MicrosoftSecurity\MicrosoftSecurity.exe /AutoIt3ExecuteScript C:\MicrosoftSecurity\Microsoft.a3x'
- <Drive name for removable media>:\microsoft\microsoft.a3x
- <Drive name for removable media>:\microsoft\microsoftsecurity.exe
- <Drive name for removable media>:\microsoft\microsoftsecurity.lnk
- <Drive name for removable media>:\microsoft\microsoftupdate.lnk
- <Drive name for removable media>:\microsoft\music.lnk
- <Drive name for removable media>:\microsoft\pictures.lnk
- <Drive name for removable media>:\microsoft\reports.lnk
- <Drive name for removable media>:\microsoft\statments.lnk
- hidden files
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "C:\MicrosoftSecurity\MicrosoftSecurity.exe" "MicrosoftSecurity.exe" ENABLE
- %LOCALAPPDATA%\tempmicrosoft.exe
- C:\totalcmd\pictures.lnk
- C:\totalcmd\music.lnk
- C:\totalcmd\totalcmd.lnk
- C:\recovery\statments.lnk
- C:\recovery\reports.lnk
- C:\recovery\pictures.lnk
- C:\recovery\music.lnk
- C:\recovery\recovery.lnk
- %ALLUSERSPROFILE%\statments.lnk
- %ALLUSERSPROFILE%\reports.lnk
- %ALLUSERSPROFILE%\pictures.lnk
- %ALLUSERSPROFILE%\music.lnk
- %ALLUSERSPROFILE%\programdata.lnk
- %ProgramFiles(x86)%\statments.lnk
- %ProgramFiles(x86)%\reports.lnk
- %ProgramFiles(x86)%\pictures.lnk
- %ProgramFiles(x86)%\music.lnk
- %ProgramFiles(x86)%\program files (x86).lnk
- %ProgramFiles%\statments.lnk
- %ProgramFiles%\reports.lnk
- %ProgramFiles%\pictures.lnk
- %ProgramFiles%\program files.lnk
- %ProgramFiles%\music.lnk
- C:\totalcmd\reports.lnk
- C:\totalcmd\statments.lnk
- D:\$recycle.bin\reports.lnk
- D:\$recycle.bin\pictures.lnk
- D:\$recycle.bin\music.lnk
- D:\$recycle.bin\$recycle.bin.lnk
- D:\microsoft\statments.lnk
- D:\microsoft\reports.lnk
- D:\microsoft\pictures.lnk
- D:\microsoft\music.lnk
- D:\microsoft\microsoftupdate.lnk
- D:\microsoft\microsoftsecurity.lnk
- D:\microsoft\microsoft.a3x
- C:\microsoftsecurity\microsoftsecurity.lnk
- %WINDIR%\statments.lnk
- %WINDIR%\reports.lnk
- %WINDIR%\pictures.lnk
- %WINDIR%\music.lnk
- %WINDIR%\windows.lnk
- C:\users\statments.lnk
- C:\users\reports.lnk
- C:\users\pictures.lnk
- C:\users\music.lnk
- %HOMEPATH%s.lnk
- C:\perflogs\statments.lnk
- C:\perflogs\reports.lnk
- C:\perflogs\pictures.lnk
- C:\documents and settings\statments.lnk
- C:\documents and settings\reports.lnk
- C:\documents and settings\pictures.lnk
- C:\documents and settings\music.lnk
- C:\documents and settings\documents and settings.lnk
- C:\$recycle.bin\statments.lnk
- C:\$recycle.bin\reports.lnk
- C:\$recycle.bin\pictures.lnk
- C:\$recycle.bin\music.lnk
- C:\$recycle.bin\$recycle.bin.lnk
- C:\microsoft\microsoftupdate.lnk
- C:\microsoft\microsoftsecurity.exe
- C:\microsoft\microsoft.a3x
- C:\microsoftsecurity\microsoftupdate.lnk
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\startup\microsoftupdate.lnk
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\startup\microsoft security.lnk
- C:\microsoftsecurity\microsoft.a3x
- %TEMP%\aut70dc.tmp
- C:\microsoftsecurity\microsoftsecurity.exe
- %TEMP%\aut7020.tmp
- C:\far2\music.lnk
- C:\far2\pictures.lnk
- C:\far2\far2.lnk
- C:\far2\reports.lnk
- C:\perflogs\music.lnk
- C:\far2\statments.lnk
- C:\perflogs\perflogs.lnk
- C:\msocache\statments.lnk
- C:\msocache\reports.lnk
- C:\msocache\pictures.lnk
- C:\msocache\music.lnk
- C:\msocache\msocache.lnk
- C:\microsoftsecurity\statments.lnk
- C:\microsoftsecurity\reports.lnk
- C:\microsoftsecurity\pictures.lnk
- D:\microsoft\microsoftsecurity.exe
- D:\$recycle.bin\statments.lnk
- C:\microsoft\statments.lnk
- C:\microsoft\reports.lnk
- C:\microsoft\pictures.lnk
- C:\microsoft\music.lnk
- C:\microsoft\microsoft.lnk
- <Current directory>\statments.lnk
- <Current directory>\reports.lnk
- <Current directory>\pictures.lnk
- <Current directory>\music.lnk
- <Current directory>\hvbie.lnk
- C:\microsoftsecurity\music.lnk
- D:\microsoft\microsoft.lnk
- %TEMP%\aut7020.tmp
- %TEMP%\aut70dc.tmp
- '%LOCALAPPDATA%\tempmicrosoft.exe'
- 'C:\microsoftsecurity\microsoftsecurity.exe' C:\MicrosoftSecurity\Microsoft.a3x
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "C:\MicrosoftSecurity\MicrosoftSecurity.exe" "MicrosoftSecurity.exe" ENABLE' (with hidden window)