Technical Information
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'SMΔRT-Protection' = '%ProgramFiles(x86)%\Smadav\SMΔRTP.exe rts'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Smadav-Updater.exe] 'Debugger' = 'SysTray.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SmadavHelper.exe] 'Debugger' = 'SysTray.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\software_reporter_tool.exe] 'Debugger' = 'SysTray.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SmadavUpdateMain.exe] 'Debugger' = 'SysTray.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Smadav-Updater.exe] 'Debugger' = 'SysTray.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SmadavUpdateMain.exe] 'Debugger' = 'SysTray.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SmadavHelper.exe] 'Debugger' = 'SysTray.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\software_reporter_tool.exe] 'Debugger' = 'SysTray.exe'
- <SYSTEM32>\tasks\smadav
- '%WINDIR%\syswow64\taskkill.exe' /f /im SMΔRTP.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im SmadavProtect32.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im SmadavProtect64.exe
- <SYSTEM32>\cmd.exe
- <SYSTEM32>\msiexec.exe
- iexplore.exe
- firefox.exe
- %TEMP%\rarsfx0\kill.exe
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\smadav antivirus\smadav.lnk
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\smadav antivirus\uninstall smadav.lnk
- C:\users\public\desktop\smadδv.lnk
- %ProgramFiles(x86)%\smadav\unins000.dat
- %APPDATA%\smadav\smadav.xml
- %TEMP%\4bde.tmp\4bdf.tmp\4be0.bat
- %TEMP%\rarsfx1\regconvert.exe
- %TEMP%\is-0rg39.tmp\_isetup\_setup64.tmp
- %TEMP%\rarsfx1\regconvert.ini
- %TEMP%\rarsfx1\salazar.ico
- %TEMP%\rarsfx1\setup.bat
- %TEMP%\rarsfx1\salazar.reg
- %TEMP%\6cd6.tmp\6ce6.tmp\6ce7.bat
- %TEMP%\rarsfx1\install.exe
- %TEMP%\rarsfx1\setup.exe
- %TEMP%\rarsfx1\setup.ico
- %ProgramFiles(x86)%\smadav\is-f94p8.tmp
- %ProgramFiles(x86)%\smadav\is-1b4ev.tmp
- %ProgramFiles(x86)%\smadav\is-daqro.tmp
- %ProgramFiles(x86)%\smadav\is-p6sut.tmp
- %ProgramFiles(x86)%\smadav\is-scood.tmp
- %TEMP%\rarsfx0\smadav.ico
- %TEMP%\rarsfx0\setup.bat
- %TEMP%\rarsfx0\update.bat
- %TEMP%\rarsfx0\update.exe
- %TEMP%\rarsfx0\activar.exe
- %TEMP%\rarsfx0\block.bat
- %TEMP%\rarsfx0\smadav.exe
- %TEMP%\rarsfx1\user.exe
- %TEMP%\rarsfx1\salazar.exe
- %TEMP%\is-4bi0c.tmp\smadav.tmp
- %ProgramFiles(x86)%\smadav\is-7ofna.tmp
- %ProgramFiles(x86)%\smadav\is-fcevm.tmp
- %ProgramFiles(x86)%\smadav\is-obous.tmp
- %ProgramFiles(x86)%\smadav\is-aen52.tmp
- %ProgramFiles(x86)%\smadav\is-pfjna.tmp
- %ProgramFiles(x86)%\smadav\is-oa6ip.tmp
- %ProgramFiles(x86)%\smadav\is-t60tb.tmp
- %TEMP%\rarsfx0\setup.exe
- %TEMP%\is-0rg39.tmp\_isetup\_shfoldr.dll
- %TEMP%\7c50.tmp\7c51.tmp\7c52.bat
- %TEMP%\is-0rg39.tmp\_isetup\_setup64.tmp
- %TEMP%\is-0rg39.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-4bi0c.tmp\smadav.tmp
- %ProgramFiles(x86)%\smadav\smadav-updater.exe
- %ProgramFiles(x86)%\smadav\smadavhelper.exe
- %APPDATA%\smadav\smadav.xml
- %TEMP%\4bde.tmp\4bdf.tmp\4be0.bat
- %TEMP%\6cd6.tmp\6ce6.tmp\6ce7.bat
- %TEMP%\rarsfx1\regconvert.exe
- %TEMP%\rarsfx1\regconvert.ini
- %TEMP%\rarsfx1\salazar.exe
- %TEMP%\rarsfx1\salazar.ico
- %TEMP%\rarsfx1\salazar.reg
- %TEMP%\rarsfx1\setup.bat
- from %ProgramFiles(x86)%\smadav\is-7ofna.tmp to %ProgramFiles(x86)%\smadav\unins000.exe
- from %ProgramFiles(x86)%\smadav\is-fcevm.tmp to %ProgramFiles(x86)%\smadav\readme.txt
- from %ProgramFiles(x86)%\smadav\is-obous.tmp to %ProgramFiles(x86)%\smadav\smδrtp.exe
- from %ProgramFiles(x86)%\smadav\is-aen52.tmp to %ProgramFiles(x86)%\smadav\smadav.loov
- from %ProgramFiles(x86)%\smadav\is-pfjna.tmp to %ProgramFiles(x86)%\smadav\smadav-updater.exe
- from %ProgramFiles(x86)%\smadav\is-oa6ip.tmp to %ProgramFiles(x86)%\smadav\smadengine.dll
- from %ProgramFiles(x86)%\smadav\is-t60tb.tmp to %ProgramFiles(x86)%\smadav\smadextmenu64.dll
- from %ProgramFiles(x86)%\smadav\is-scood.tmp to %ProgramFiles(x86)%\smadav\smadhook32c.dll
- from %ProgramFiles(x86)%\smadav\is-p6sut.tmp to %ProgramFiles(x86)%\smadav\smadhook64c.dll
- from %ProgramFiles(x86)%\smadav\is-daqro.tmp to %ProgramFiles(x86)%\smadav\smadavprotect32.exe
- from %ProgramFiles(x86)%\smadav\is-f94p8.tmp to %ProgramFiles(x86)%\smadav\smadavprotect64.exe
- from %ProgramFiles(x86)%\smadav\is-1b4ev.tmp to %ProgramFiles(x86)%\smadav\smadavhelper.exe
- %TEMP%\rarsfx1\setup.bat
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'ThunderRT6Main' WindowName: 'S m a d a v '
- ClassName: '' WindowName: 'SmaRTP'
- ClassName: 'ThunderRT6TextBox' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: '' WindowName: 'SmadHook32'
- ClassName: '' WindowName: 'SmadHook64'
- ClassName: '' WindowName: 'Windows Script Host'
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- '%TEMP%\rarsfx0\smadav.exe' /VERYSILENT
- '%TEMP%\is-4bi0c.tmp\smadav.tmp' /SL5="$1024C,5960114,133120,%TEMP%\RarSFX0\smadav.exe" /VERYSILENT
- '%ProgramFiles(x86)%\smadav\smδrtp.exe' rtc
- '%TEMP%\rarsfx0\update.exe'
- '%ProgramFiles(x86)%\smadav\smadavprotect64.exe'
- '%TEMP%\rarsfx0\activar.exe'
- '%ProgramFiles(x86)%\smadav\smδrtp.exe'
- '%TEMP%\rarsfx1\salazar.exe'
- '%TEMP%\rarsfx0\kill.exe'
- '%TEMP%\rarsfx1\install.exe'
- '%TEMP%\rarsfx1\setup.exe' /Silent
- '%WINDIR%\syswow64\taskkill.exe' /f /im SMΔRTP.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im SmadavProtect32.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im SmadavProtect64.exe' (with hidden window)
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "smadav" /xml "%APPDATA%\Smadav\smadav.xml"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\4BDE.tmp\4BDF.tmp\4BE0.bat %TEMP%\RarSFX0\Update.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\RarSFX0\Setup.bat" "
- '%WINDIR%\syswow64\mode.com' con:cols=58 lines=8
- '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles(x86)%\SMADAV\SmadExtMenu64.dll"
- '%WINDIR%\syswow64\timeout.exe' /T 01
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "smadav" /xml "%APPDATA%\Smadav\smadav.xml"
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\4BDE.tmp\4BDF.tmp\4BE0.bat %TEMP%\RarSFX0\Update.exe"
- '<SYSTEM32>\mode.com' con:cols=58 lines=8
- '<SYSTEM32>\timeout.exe' /T 01
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\6CD6.tmp\6CE6.tmp\6CE7.bat %TEMP%\RarSFX1\Salazar.exe"
- '%WINDIR%\regedit.exe' /s Salazar.reg
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\7C50.tmp\7C51.tmp\7C52.bat %TEMP%\RarSFX1\install.exe"
- '<SYSTEM32>\mode.com' con:cols=58 lines=10