Technical Information
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'audiodg' = '"C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\audiodg.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'csrss' = '"C:\Users\Public\csrss.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'Idle' = '"%WINDIR%\ModemLogs\Idle.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'wininit' = '"%WINDIR%\Installer\{EB9BD1D5-8DFB-48C4-927B-10BB47CA59B3}\wininit.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'audiodg' = '"C:\totalcmd\LANGUAGE\audiodg.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'lsm' = '"C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\lsm.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'audiodg' = '"C:\Users\Default\Cookies\audiodg.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'WmiPrvSE' = '"C:\Far2\Encyclopedia\tap\WmiPrvSE.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'explorer' = '"C:\totalcmd\LANGUAGE\explorer.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'wininit' = '"%ProgramFiles%\ashUpd\wininit.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'smss' = '"<Current directory>\smss.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'lsm' = '"C:\Documents and Settings\lsm.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'msiexec' = '"%ProgramFiles%\ppfw\msiexec.exe"'
- [<HKLM>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe, "C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\audiodg.exe", "C:\Users\Default\Links\lsm.exe", "%WINDI...
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'firefox' = '"%WINDIR%\addins\firefox.exe"'
- [<HKLM>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe, "C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\audiodg.exe", "C:\Users\Default\Links\lsm.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'lsm' = '"C:\Users\Default\Links\lsm.exe"'
- [<HKLM>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe, "C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\audiodg.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'audiodg' = '"C:\Far2\FExcept\audiodg.exe"'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'lsass' = '"C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\lsass.exe"'
- <SYSTEM32>\tasks\cxtgaudiodg
- <SYSTEM32>\tasks\wmiprvse
- <SYSTEM32>\tasks\wh0jaudiodg
- <SYSTEM32>\tasks\ai9maudiodg
- <SYSTEM32>\tasks\fmpylsm
- <SYSTEM32>\tasks\yzi2audiodg
- <SYSTEM32>\tasks\l8umlsm
- <SYSTEM32>\tasks\vygdlsm
- <SYSTEM32>\tasks\k8pnaudiodg
- <SYSTEM32>\tasks\i6gblsm
- <SYSTEM32>\tasks\ihhzaudiodg
- <SYSTEM32>\tasks\1zrmlsm
- <SYSTEM32>\tasks\xnb9lsm
- <SYSTEM32>\tasks\nufiaudiodg
- <SYSTEM32>\tasks\l6nowininit
- <SYSTEM32>\tasks\izhgwininit
- <SYSTEM32>\tasks\jga5wininit
- <SYSTEM32>\tasks\abexidle
- <SYSTEM32>\tasks\ieicidle
- <SYSTEM32>\tasks\idle
- <SYSTEM32>\tasks\qf0mcsrss
- <SYSTEM32>\tasks\pbgbidle
- <SYSTEM32>\tasks\elazcsrss
- <SYSTEM32>\tasks\o5vlcsrss
- <SYSTEM32>\tasks\x9fiaudiodg
- <SYSTEM32>\tasks\csrss
- <SYSTEM32>\tasks\owceaudiodg
- <SYSTEM32>\tasks\9zfqlsass
- <SYSTEM32>\tasks\glsdlsass
- <SYSTEM32>\tasks\k8mzaudiodg
- <SYSTEM32>\tasks\nmyewmiprvse
- <SYSTEM32>\tasks\lsass
- <SYSTEM32>\tasks\itnfwmiprvse
- <SYSTEM32>\tasks\lwztexplorer
- <SYSTEM32>\tasks\2mqaaudiodg
- <SYSTEM32>\tasks\gf8nlsm
- <SYSTEM32>\tasks\it2wlsm
- <SYSTEM32>\tasks\audiodg
- <SYSTEM32>\tasks\cppglsm
- <SYSTEM32>\tasks\4byraudiodg
- <SYSTEM32>\tasks\wdp8firefox
- <SYSTEM32>\tasks\9bmcfirefox
- <SYSTEM32>\tasks\ooxxfirefox
- <SYSTEM32>\tasks\lsm
- <SYSTEM32>\tasks\firefox
- <SYSTEM32>\tasks\y13mmsiexec
- <SYSTEM32>\tasks\akurmsiexec
- <SYSTEM32>\tasks\enbkmsiexec
- <SYSTEM32>\tasks\ospylsm
- <SYSTEM32>\tasks\h9zolsm
- <SYSTEM32>\tasks\msiexec
- <SYSTEM32>\tasks\yfgklsm
- <SYSTEM32>\tasks\57fzsmss
- <SYSTEM32>\tasks\nxwysmss
- <SYSTEM32>\tasks\j75lsmss
- <SYSTEM32>\tasks\smss
- <SYSTEM32>\tasks\tovswininit
- <SYSTEM32>\tasks\jgkiwininit
- <SYSTEM32>\tasks\wininit
- <SYSTEM32>\tasks\qb5iwininit
- <SYSTEM32>\tasks\1x5bexplorer
- <SYSTEM32>\tasks\vrw8explorer
- <SYSTEM32>\tasks\explorer
- <SYSTEM32>\tasks\j884wmiprvse
- <SYSTEM32>\tasks\e6delsass
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\audiodg.exe
- C:\far2\encyclopedia\tap\rcxef11.tmp
- C:\totalcmd\language\rcxec91.tmp
- C:\totalcmd\language\rcxec03.tmp
- %ProgramFiles%\ashupd\rcxe973.tmp
- %ProgramFiles%\ashupd\rcxe8e6.tmp
- <Current directory>\rcxe656.tmp
- C:\users\default\cookies\rcxf22f.tmp
- C:\far2\encyclopedia\tap\rcxef9f.tmp
- C:\documents and settings\rcxe2ca.tmp
- %ProgramFiles%\ppfw\rcxe049.tmp
- %ProgramFiles%\ppfw\rcxdfcb.tmp
- %WINDIR%\addins\rcxdd3b.tmp
- %WINDIR%\addins\rcxdcbd.tmp
- C:\users\default\links\rcxda3d.tmp
- <Current directory>\rcxe5c8.tmp
- C:\users\default\cookies\audiodg.exe
- C:\users\default\cookies\rcxf2bc.tmp
- %TEMP%\yq25herlbd.bat
- %TEMP%\anlhrawd88
- C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.en\rcxa6f.tmp
- C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.en\rcx9e2.tmp
- C:\far2\fexcept\rcx752.tmp
- C:\far2\fexcept\rcx6d4.tmp
- C:\users\public\rcx444.tmp
- C:\users\public\rcx3b6.tmp
- %WINDIR%\modemlogs\rcx126.tmp
- %WINDIR%\modemlogs\rcx99.tmp
- %WINDIR%\installer\{eb9bd1d5-8dfb-48c4-927b-10bb47ca59b3}\rcxfe08.tmp
- %WINDIR%\installer\{eb9bd1d5-8dfb-48c4-927b-10bb47ca59b3}\rcxfd7b.tmp
- C:\totalcmd\language\rcxf8e8.tmp
- C:\totalcmd\language\rcxf85b.tmp
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\rcxf5ca.tmp
- C:\users\default\links\rcxd9bf.tmp
- C:\documents and settings\rcxe348.tmp
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\rcxd73e.tmp
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\rcxd6b1.tmp
- <Current directory>\rcxd47e.tmp
- C:\documents and settings\lsm.exe
- C:\totalcmd\language\explorer.exe
- %ProgramFiles%\ashupd\56085415360792
- %ProgramFiles%\ashupd\wininit.exe
- <Current directory>\69ddcba757bf72
- <Current directory>\smss.exe
- C:\documents and settings\101b941d020240
- %ProgramFiles%\ppfw\133006b48fb54b
- C:\far2\encyclopedia\tap\wmiprvse.exe
- %ProgramFiles%\ppfw\msiexec.exe
- %WINDIR%\addins\0fc223bdacedc3
- %WINDIR%\addins\firefox.exe
- C:\users\default\links\101b941d020240
- C:\users\default\links\lsm.exe
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\42af1c969fbb7b
- nul
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\rcxf53d.tmp
- C:\far2\encyclopedia\tap\24dbde2999530e
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\lsm.exe
- C:\totalcmd\language\7a0fd90576e088
- <Current directory>\rcxd401.tmp
- C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.en\6203df4a6bafc7
- C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.en\lsass.exe
- C:\far2\fexcept\42af1c969fbb7b
- C:\far2\fexcept\audiodg.exe
- C:\users\public\886983d96e3d3e
- C:\users\public\csrss.exe
- %WINDIR%\modemlogs\6ccacd8608530f
- %WINDIR%\modemlogs\idle.exe
- %WINDIR%\installer\{eb9bd1d5-8dfb-48c4-927b-10bb47ca59b3}\56085415360792
- %WINDIR%\installer\{eb9bd1d5-8dfb-48c4-927b-10bb47ca59b3}\wininit.exe
- C:\totalcmd\language\42af1c969fbb7b
- C:\totalcmd\language\audiodg.exe
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\101b941d020240
- C:\users\default\cookies\42af1c969fbb7b
- %TEMP%\tmp706e.tmp
- <Full path to file>
- C:\users\public\csrss.exe
- %WINDIR%\modemlogs\idle.exe
- %WINDIR%\installer\{eb9bd1d5-8dfb-48c4-927b-10bb47ca59b3}\wininit.exe
- C:\totalcmd\language\audiodg.exe
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\lsm.exe
- C:\users\default\cookies\audiodg.exe
- C:\far2\encyclopedia\tap\wmiprvse.exe
- C:\totalcmd\language\explorer.exe
- %ProgramFiles%\ashupd\wininit.exe
- <Current directory>\smss.exe
- C:\documents and settings\lsm.exe
- %ProgramFiles%\ppfw\msiexec.exe
- %WINDIR%\addins\firefox.exe
- C:\users\default\links\lsm.exe
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\audiodg.exe
- C:\far2\fexcept\audiodg.exe
- C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.en\lsass.exe
- %TEMP%\anlhrawd88
- from <Current directory>\rcxd47e.tmp to <Full path to file>
- from C:\users\default\cookies\rcxf22f.tmp to C:\users\default\cookies\audiodg.exe
- from C:\users\default\cookies\rcxf2bc.tmp to C:\users\default\cookies\audiodg.exe
- from C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\rcxf53d.tmp to C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\lsm.exe
- from C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\rcxf5ca.tmp to C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\lsm.exe
- from C:\totalcmd\language\rcxf85b.tmp to C:\totalcmd\language\audiodg.exe
- from C:\totalcmd\language\rcxf8e8.tmp to C:\totalcmd\language\audiodg.exe
- from %WINDIR%\installer\{eb9bd1d5-8dfb-48c4-927b-10bb47ca59b3}\rcxfe08.tmp to %WINDIR%\installer\{eb9bd1d5-8dfb-48c4-927b-10bb47ca59b3}\wininit.exe
- from C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.en\rcx9e2.tmp to C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.en\lsass.exe
- from %WINDIR%\modemlogs\rcx99.tmp to %WINDIR%\modemlogs\idle.exe
- from %WINDIR%\modemlogs\rcx126.tmp to %WINDIR%\modemlogs\idle.exe
- from C:\users\public\rcx3b6.tmp to C:\users\public\csrss.exe
- from C:\users\public\rcx444.tmp to C:\users\public\csrss.exe
- from C:\far2\fexcept\rcx6d4.tmp to C:\far2\fexcept\audiodg.exe
- from C:\far2\fexcept\rcx752.tmp to C:\far2\fexcept\audiodg.exe
- from C:\far2\encyclopedia\tap\rcxef9f.tmp to C:\far2\encyclopedia\tap\wmiprvse.exe
- from %WINDIR%\installer\{eb9bd1d5-8dfb-48c4-927b-10bb47ca59b3}\rcxfd7b.tmp to %WINDIR%\installer\{eb9bd1d5-8dfb-48c4-927b-10bb47ca59b3}\wininit.exe
- from C:\far2\encyclopedia\tap\rcxef11.tmp to C:\far2\encyclopedia\tap\wmiprvse.exe
- from %ProgramFiles%\ppfw\rcxdfcb.tmp to %ProgramFiles%\ppfw\msiexec.exe
- from C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\rcxd6b1.tmp to C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\audiodg.exe
- from C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\rcxd73e.tmp to C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\audiodg.exe
- from C:\users\default\links\rcxd9bf.tmp to C:\users\default\links\lsm.exe
- from C:\users\default\links\rcxda3d.tmp to C:\users\default\links\lsm.exe
- from %WINDIR%\addins\rcxdcbd.tmp to %WINDIR%\addins\firefox.exe
- from %WINDIR%\addins\rcxdd3b.tmp to %WINDIR%\addins\firefox.exe
- from %ProgramFiles%\ppfw\rcxe049.tmp to %ProgramFiles%\ppfw\msiexec.exe
- from C:\totalcmd\language\rcxec03.tmp to C:\totalcmd\language\explorer.exe
- from C:\documents and settings\rcxe2ca.tmp to C:\documents and settings\lsm.exe
- from C:\documents and settings\rcxe348.tmp to C:\documents and settings\lsm.exe
- from <Current directory>\rcxe5c8.tmp to <Current directory>\smss.exe
- from <Current directory>\rcxe656.tmp to <Current directory>\smss.exe
- from %ProgramFiles%\ashupd\rcxe8e6.tmp to %ProgramFiles%\ashupd\wininit.exe
- from %ProgramFiles%\ashupd\rcxe973.tmp to %ProgramFiles%\ashupd\wininit.exe
- from C:\totalcmd\language\rcxec91.tmp to C:\totalcmd\language\explorer.exe
- from C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.en\rcxa6f.tmp to C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.en\lsass.exe
- 'h1#####.srv13.test-hf.su':80
- 'ip##fo.io':443
- 'ap#.##legram.org':443
- http://h1#####.srv13.test-hf.su/externalphpLow.php?lN############################################################################################################################################...
- http://h1#####.srv13.test-hf.su/externalphpLow.php?L2############################################################################################################################################...
- 'ip##fo.io':443
- 'ap#.##legram.org':443
- DNS ASK h1#####.srv13.test-hf.su
- DNS ASK ip##fo.io
- DNS ASK ap#.##legram.org
- 'localhost':123
- 'C:\users\default\cookies\audiodg.exe'
- '<SYSTEM32>\cmd.exe' /C "%TEMP%\yQ25hERLBD.bat"' (with hidden window)
- '<SYSTEM32>\schtasks.exe' /create /tn "CxTGaudiodg" /sc MINUTE /mo 8 /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\audiodg.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "L6nOwininit" /sc MINUTE /mo 14 /tr "'%WINDIR%\Installer\{EB9BD1D5-8DFB-48C4-927B-10BB47CA59B3}\wininit.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "lsm" /sc MINUTE /mo 7 /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\lsm.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "XNb9lsm" /sc ONSTART /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\lsm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "1zRMlsm" /sc ONLOGON /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\lsm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "i6gblsm" /sc MINUTE /mo 10 /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\lsm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "audiodg" /sc MINUTE /mo 10 /tr "'C:\totalcmd\LANGUAGE\audiodg.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "JgA5wininit" /sc ONSTART /tr "'%WINDIR%\Installer\{EB9BD1D5-8DFB-48C4-927B-10BB47CA59B3}\wininit.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "IZHgwininit" /sc ONLOGON /tr "'%WINDIR%\Installer\{EB9BD1D5-8DFB-48C4-927B-10BB47CA59B3}\wininit.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "K8pNaudiodg" /sc MINUTE /mo 13 /tr "'C:\totalcmd\LANGUAGE\audiodg.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "lsm" /sc MINUTE /mo 12 /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\lsm.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "vYgdlsm" /sc ONSTART /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\lsm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "l8Umlsm" /sc ONLOGON /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\lsm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "FMpYlsm" /sc MINUTE /mo 14 /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\lsm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "audiodg" /sc MINUTE /mo 5 /tr "'C:\Users\Default\Cookies\audiodg.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "NUfiaudiodg" /sc ONSTART /tr "'C:\totalcmd\LANGUAGE\audiodg.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "yfGklsm" /sc ONSTART /tr "'C:\Documents and Settings\lsm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "wininit" /sc MINUTE /mo 11 /tr "'%WINDIR%\Installer\{EB9BD1D5-8DFB-48C4-927B-10BB47CA59B3}\wininit.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "lsass" /sc MINUTE /mo 7 /tr "'C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\lsass.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "e6dElsass" /sc ONSTART /tr "'C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\lsass.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "9zfqlsass" /sc ONLOGON /tr "'C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\lsass.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "glSdlsass" /sc MINUTE /mo 8 /tr "'C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\lsass.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "audiodg" /sc MINUTE /mo 7 /tr "'C:\Far2\FExcept\audiodg.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "K8mzaudiodg" /sc ONSTART /tr "'C:\Far2\FExcept\audiodg.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "x9fiaudiodg" /sc ONLOGON /tr "'C:\Far2\FExcept\audiodg.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "OwCEaudiodg" /sc MINUTE /mo 13 /tr "'C:\Far2\FExcept\audiodg.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "csrss" /sc MINUTE /mo 14 /tr "'C:\Users\Public\csrss.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "qF0Mcsrss" /sc ONSTART /tr "'C:\Users\Public\csrss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "elaZcsrss" /sc ONLOGON /tr "'C:\Users\Public\csrss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "o5vLcsrss" /sc MINUTE /mo 11 /tr "'C:\Users\Public\csrss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "Idle" /sc MINUTE /mo 5 /tr "'%WINDIR%\ModemLogs\Idle.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "ABExIdle" /sc ONSTART /tr "'%WINDIR%\ModemLogs\Idle.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "IeIcIdle" /sc ONLOGON /tr "'%WINDIR%\ModemLogs\Idle.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "Yzi2audiodg" /sc ONSTART /tr "'C:\Users\Default\Cookies\audiodg.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "IHHZaudiodg" /sc ONLOGON /tr "'C:\totalcmd\LANGUAGE\audiodg.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "Wh0jaudiodg" /sc ONLOGON /tr "'C:\Users\Default\Cookies\audiodg.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "Ai9maudiodg" /sc MINUTE /mo 13 /tr "'C:\Users\Default\Cookies\audiodg.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "WmiPrvSE" /sc MINUTE /mo 5 /tr "'C:\Far2\Encyclopedia\tap\WmiPrvSE.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "9bMCfirefox" /sc MINUTE /mo 14 /tr "'%WINDIR%\addins\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "y13mmsiexec" /sc ONSTART /tr "'%ProgramFiles%\ppfw\msiexec.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "AkUrmsiexec" /sc ONLOGON /tr "'%ProgramFiles%\ppfw\msiexec.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "eNbKmsiexec" /sc MINUTE /mo 13 /tr "'%ProgramFiles%\ppfw\msiexec.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "firefox" /sc MINUTE /mo 11 /tr "'%WINDIR%\addins\firefox.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "ooXxfirefox" /sc ONSTART /tr "'%WINDIR%\addins\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "wdP8firefox" /sc ONLOGON /tr "'%WINDIR%\addins\firefox.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "lsm" /sc MINUTE /mo 11 /tr "'C:\Users\Default\Links\lsm.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "h9ZOlsm" /sc MINUTE /mo 13 /tr "'C:\Documents and Settings\lsm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "cPPGlsm" /sc ONSTART /tr "'C:\Users\Default\Links\lsm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "IT2wlsm" /sc ONLOGON /tr "'C:\Users\Default\Links\lsm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "gf8nlsm" /sc MINUTE /mo 5 /tr "'C:\Users\Default\Links\lsm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "audiodg" /sc MINUTE /mo 9 /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\audiodg.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "4Byraudiodg" /sc ONSTART /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\audiodg.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "2mQaaudiodg" /sc ONLOGON /tr "'C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\audiodg.exe'" /rl HIGHEST /f
- '<SYSTEM32>\cmd.exe' /C "%TEMP%\yQ25hERLBD.bat"
- '<SYSTEM32>\schtasks.exe' /create /tn "PBgBIdle" /sc MINUTE /mo 8 /tr "'%WINDIR%\ModemLogs\Idle.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "OSPYlsm" /sc ONLOGON /tr "'C:\Documents and Settings\lsm.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "nxWysmss" /sc MINUTE /mo 8 /tr "'<Current directory>\smss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "msiexec" /sc MINUTE /mo 7 /tr "'%ProgramFiles%\ppfw\msiexec.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "nMyeWmiPrvSE" /sc ONSTART /tr "'C:\Far2\Encyclopedia\tap\WmiPrvSE.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "J884WmiPrvSE" /sc ONLOGON /tr "'C:\Far2\Encyclopedia\tap\WmiPrvSE.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "itnfWmiPrvSE" /sc MINUTE /mo 13 /tr "'C:\Far2\Encyclopedia\tap\WmiPrvSE.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "explorer" /sc MINUTE /mo 11 /tr "'C:\totalcmd\LANGUAGE\explorer.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "LwZTexplorer" /sc ONSTART /tr "'C:\totalcmd\LANGUAGE\explorer.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "vRW8explorer" /sc ONLOGON /tr "'C:\totalcmd\LANGUAGE\explorer.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "1x5Bexplorer" /sc MINUTE /mo 9 /tr "'C:\totalcmd\LANGUAGE\explorer.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "wininit" /sc MINUTE /mo 12 /tr "'%ProgramFiles%\ashUpd\wininit.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "qb5Iwininit" /sc ONSTART /tr "'%ProgramFiles%\ashUpd\wininit.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "JgKIwininit" /sc ONLOGON /tr "'%ProgramFiles%\ashUpd\wininit.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "TOVSwininit" /sc MINUTE /mo 6 /tr "'%ProgramFiles%\ashUpd\wininit.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "smss" /sc MINUTE /mo 14 /tr "'<Current directory>\smss.exe'" /f
- '<SYSTEM32>\schtasks.exe' /create /tn "J75Lsmss" /sc ONSTART /tr "'<Current directory>\smss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "57FZsmss" /sc ONLOGON /tr "'<Current directory>\smss.exe'" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "lsm" /sc MINUTE /mo 12 /tr "'C:\Documents and Settings\lsm.exe'" /f
- '<SYSTEM32>\w32tm.exe' /stripchart /computer:localhost /period:5 /dataonly /samples:2