Technical Information
- [<HKLM>\System\CurrentControlSet\Services\AntiCheatExpert Services] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\AntiCheatExpert Services] 'ImagePath' = '<Full path to file>'
- [<HKLM>\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%WINDIR%\TEMP\UpdatePatch\WinRing0x64.sys'
- 'AntiCheatExpert Services' <Full path to file>
- 'WinRing0_1_2_0' %WINDIR%\TEMP\UpdatePatch\WinRing0x64.sys
- '%WINDIR%\syswow64\at.exe' /delete /yes
- %TEMP%\killminer.bat
- %WINDIR%\temp\killminer.bat
- %WINDIR%\temp\updatepatch\applicationframehost.exe
- %WINDIR%\temp\updatepatch\winring0x64.sys
- %WINDIR%\temp\udda302.tmp
- <Full path to file>
- %WINDIR%\temp\updatepatch\applicationframehost.exe
- %WINDIR%\temp\updatepatch\winring0x64.sys
- %TEMP%\killminer.bat
- <SYSTEM32>\tasks\microsoft\windows\sideshow\autowake
- <SYSTEM32>\tasks\microsoft\windows\shell\windowsparentalcontrolsmigration
- <SYSTEM32>\tasks\microsoft\windows\shell\windowsparentalcontrols
- <SYSTEM32>\tasks\microsoft\windows\remoteassistance\remoteassistancetask
- <SYSTEM32>\tasks\microsoft\windows\registry\regidlebackup
- <SYSTEM32>\tasks\microsoft\windows\ras\mobilitymanager
- <SYSTEM32>\tasks\microsoft\windows\rac\ractask
- <SYSTEM32>\tasks\microsoft\windows\power efficiency diagnostics\analyzesystem
- <SYSTEM32>\tasks\microsoft\windows\perftrack\backgroundconfigsurveyor
- <SYSTEM32>\tasks\microsoft\windows\offline files\logon synchronization
- <SYSTEM32>\tasks\microsoft\windows\offline files\background synchronization
- <SYSTEM32>\tasks\microsoft\windows\nettrace\gathernetworkinfo
- <SYSTEM32>\tasks\microsoft\windows\multimedia\systemsoundsservice
- <SYSTEM32>\tasks\microsoft\windows\mui\lpremove
- <SYSTEM32>\tasks\microsoft\windows\mobilepc\hotstart
- <SYSTEM32>\tasks\microsoft\windows\memorydiagnostic\decompressionfailuredetector
- <SYSTEM32>\tasks\microsoft\windows\memorydiagnostic\corruptiondetector
- <SYSTEM32>\tasks\microsoft\windows\media center\sqlliterecoverytask
- <SYSTEM32>\tasks\microsoft\windows\media center\updaterecordpath
- <SYSTEM32>\tasks\microsoft\windows\sideshow\gadgetmanager
- <SYSTEM32>\tasks\microsoft\windows\sideshow\sessionagent
- %WINDIR%\tasks\sa.dat
- <SYSTEM32>\tasks\officesoftwareprotectionplatform\svcrestarttask
- <SYSTEM32>\tasks\microsoft\windows\windowscolorsystem\calibration loader
- <SYSTEM32>\tasks\microsoft\windows\windowsbackup\confignotification
- <SYSTEM32>\tasks\microsoft\windows\windows media sharing\updatelibrary
- <SYSTEM32>\tasks\microsoft\windows\windows filtering platform\bfeonservicestarttypechange
- <SYSTEM32>\tasks\microsoft\windows\windows error reporting\queuereporting
- <SYSTEM32>\tasks\microsoft\windows\wdi\resolutionhost
- <SYSTEM32>\tasks\microsoft\windows\upnp\upnphostconfig
- <SYSTEM32>\tasks\microsoft\windows\media center\mediacenterrecoverytask
- <SYSTEM32>\tasks\microsoft\windows\time synchronization\synchronizetime
- <SYSTEM32>\tasks\microsoft\windows\textservicesframework\msctfmonitor
- <SYSTEM32>\tasks\microsoft\windows\tcpip\ipaddressconflict2
- <SYSTEM32>\tasks\microsoft\windows\tcpip\ipaddressconflict1
- <SYSTEM32>\tasks\microsoft\windows\task manager\interactive
- <SYSTEM32>\tasks\microsoft\windows\systemrestore\sr
- <SYSTEM32>\tasks\microsoft\windows\softwareprotectionplatform\svcrestarttask
- <SYSTEM32>\tasks\microsoft\windows\sideshow\systemdataproviders
- <SYSTEM32>\tasks\microsoft\windows\media center\reindexsearchroot
- <SYSTEM32>\tasks\microsoft\windows\media center\registersearch
- <SYSTEM32>\tasks\microsoft\windows\media center\recordingrestart
- <SYSTEM32>\tasks\microsoft\windows\customer experience improvement program\kernelceiptask
- <SYSTEM32>\tasks\microsoft\windows\customer experience improvement program\consolidator
- <SYSTEM32>\tasks\microsoft\windows\certificateservicesclient\usertask-roam
- <SYSTEM32>\tasks\microsoft\windows\certificateservicesclient\usertask
- <SYSTEM32>\tasks\microsoft\windows\certificateservicesclient\systemtask
- <SYSTEM32>\tasks\microsoft\windows\bluetooth\uninstalldevicetask
- <SYSTEM32>\tasks\microsoft\windows\autochk\proxy
- <SYSTEM32>\tasks\microsoft\windows\application experience\programdataupdater
- <SYSTEM32>\tasks\microsoft\windows\application experience\aitagent
- <SYSTEM32>\tasks\microsoft\windows\appid\verifiedpublishercertstorecheck
- <SYSTEM32>\tasks\microsoft\windows\appid\policyconverter
- <SYSTEM32>\tasks\microsoft\windows\active directory rights management services client\ad rms rights policy template management (manual)
- <SYSTEM32>\tasks\microsoft\windows\active directory rights management services client\ad rms rights policy template management (automated)
- <SYSTEM32>\tasks\adobe flash player updater
- %WINDIR%\tasks\adobe flash player updater.job
- <SYSTEM32>\tasks\adobe acrobat update task
- <SYSTEM32>\tasks\microsoft\windows\defrag\scheduleddefrag
- <SYSTEM32>\tasks\microsoft\windows\diagnosis\scheduled
- <SYSTEM32>\tasks\microsoft\windows\customer experience improvement program\usbceip
- <SYSTEM32>\tasks\microsoft\windows\diskdiagnostic\microsoft-windows-diskdiagnosticdatacollector
- <SYSTEM32>\tasks\microsoft\windows\media center\pvrscheduletask
- <SYSTEM32>\tasks\microsoft\windows\diskdiagnostic\microsoft-windows-diskdiagnosticresolver
- <SYSTEM32>\tasks\microsoft\windows\media center\pvrrecoverytask
- <SYSTEM32>\tasks\microsoft\windows\media center\periodicscanretry
- <SYSTEM32>\tasks\microsoft\windows\media center\pbdadiscoveryw2
- <SYSTEM32>\tasks\microsoft\windows\media center\pbdadiscoveryw1
- <SYSTEM32>\tasks\microsoft\windows\media center\pbdadiscovery
- <SYSTEM32>\tasks\microsoft\windows\media center\ocurdiscovery
- <SYSTEM32>\tasks\microsoft\windows\media center\ocuractivate
- <SYSTEM32>\tasks\microsoft\windows\user profile service\hiveuploadtask
- %WINDIR%\temp\killminer.bat
- <SYSTEM32>\tasks\microsoft\windows\media center\mcupdate
- <SYSTEM32>\tasks\microsoft\windows\media center\installplayready
- <SYSTEM32>\tasks\microsoft\windows\media center\ehdrminit
- <SYSTEM32>\tasks\microsoft\windows\media center\dispatchrecoverytasks
- <SYSTEM32>\tasks\microsoft\windows\media center\configureinternettimeservice
- <SYSTEM32>\tasks\microsoft\windows\media center\activatewindowssearch
- <SYSTEM32>\tasks\microsoft\windows\maintenance\winsat
- <SYSTEM32>\tasks\microsoft\windows\location\notifications
- <SYSTEM32>\tasks\microsoft\windows\media center\objectstorerecoverytask
- %WINDIR%\temp\udda302.tmp
- %TEMP%\killminer.bat
- %WINDIR%\temp\killminer.bat
- 'ne####.1392010.net':443
- DNS ASK ne####.1392010.net
- '%WINDIR%\temp\updatepatch\applicationframehost.exe'
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\\KillMiner.bat' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c SCHTASKS /Delete /TN * /F' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c at /delete /yes' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c %WINDIR%\TEMP\\KillMiner.bat' (with hidden window)
- '%WINDIR%\temp\updatepatch\applicationframehost.exe' ' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\\KillMiner.bat
- '%WINDIR%\syswow64\cmd.exe' /S /D /c" echo Y"
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\IME\Microsoft /T /D users
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\IME\Microsoft /T /D administrators
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\IME\Microsoft /T /D SYSTEM
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\IME\Crypt /T /D users
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\IME\Crypt /T /D administrators
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\IME\Crypt /T /D SYSTEM
- '%WINDIR%\syswow64\cmd.exe' /c SCHTASKS /Delete /TN * /F
- '%WINDIR%\syswow64\schtasks.exe' /Delete /TN * /F
- '%WINDIR%\syswow64\cmd.exe' /c at /delete /yes
- '%WINDIR%\syswow64\cmd.exe' /c %WINDIR%\TEMP\\KillMiner.bat