Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = '%LOCALAPPDATA%\wcu.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = '%LOCALAPPDATA%\wcu.exe'
- %WINDIR%\regedit.exe
- %WINDIR%\notepad.exe
- <SYSTEM32>\resmon.exe
- <SYSTEM32>\perfmon.exe
- <SYSTEM32>\calc.exe
- <SYSTEM32>\notepad.exe
- <SYSTEM32>\taskmgr.exe
- <SYSTEM32>\sethc.exe
- <SYSTEM32>\mmc.exe
- <SYSTEM32>\narrator.exe
- <SYSTEM32>\mspaint.exe
- <SYSTEM32>\dxdiag.exe
- <SYSTEM32>\regedt32.exe
- <SYSTEM32>\dism.exe
- <SYSTEM32>\sfc.exe
- Command Prompt (CMD)
- Windows Task Manager (Taskmgr)
- Windows Firewall
- Windows Update
- Windows Defender
- User Account Control (UAC)
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoRun' = '00000001'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoRun' = '00000001'
- %WINDIR%\explorer.exe
- firefox.exe
- %LOCALAPPDATA%\wcu.exe
- <SYSTEM32>\sfc.dll
- <SYSTEM32>\taskschd.msc
- <SYSTEM32>\services.msc
- 'localhost':58598
- 'localhost':52964
- ClassName: 'Progman' WindowName: ''
- ClassName: 'Proxy Desktop' WindowName: ''
- ClassName: 'SystemTray_Main' WindowName: ''
- ClassName: 'Media Center Tray Applet' WindowName: ''
- ClassName: '' WindowName: 'View Available Networks'
- ClassName: 'BluetoothNotificationAreaIconWindowClass' WindowName: 'BluetoothNotificationAreaIconWindowClass'
- ClassName: 'BluetoothNotificationAreaIconWindowClass' WindowName: ''
- '%LOCALAPPDATA%\wcu.exe'
- '<SYSTEM32>\takeown.exe' /f "%WINDIR%\regedit.exe"' (with hidden window)
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\regedt32.exe"' (with hidden window)
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\regedt32.exe" /grant "nppetaa\user:(F)" /t' (with hidden window)
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\dism.exe"' (with hidden window)
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\dism.exe" /grant "nppetaa\user:(F)" /t' (with hidden window)
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\sfc.exe"' (with hidden window)
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\sfc.exe" /grant "nppetaa\user:(F)" /t' (with hidden window)
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\sfc.dll"' (with hidden window)
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\sfc.dll" /grant "nppetaa\user:(F)" /t' (with hidden window)
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\taskschd.msc"' (with hidden window)
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\taskschd.msc" /grant "nppetaa\user:(F)" /t' (with hidden window)
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\services.msc"' (with hidden window)
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\services.msc" /grant "nppetaa\user:(F)" /t' (with hidden window)
- '<SYSTEM32>\takeown.exe' /f "%ProgramFiles%\Windows Defender" /r /d n' (with hidden window)
- '<SYSTEM32>\icacls.exe' "%ProgramFiles%\Windows Defender" /grant "nppetaa\user:(F)" /t' (with hidden window)
- '<SYSTEM32>\takeown.exe' /f "%ProgramFiles(x86)%\Windows Defender" /r /d n' (with hidden window)
- '<SYSTEM32>\icacls.exe' "%ProgramFiles(x86)%\Windows Defender" /grant "nppetaa\user:(F)" /t' (with hidden window)
- '<SYSTEM32>\takeown.exe' /f "%ALLUSERSPROFILE%\Microsoft\Windows Defender" /r /d n' (with hidden window)
- '<SYSTEM32>\icacls.exe' "%ALLUSERSPROFILE%\Microsoft\Windows Defender" /grant "nppetaa\user:(F)" /t' (with hidden window)
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\dxdiag.exe" /grant "nppetaa\user:(F)" /t' (with hidden window)
- '<SYSTEM32>\takeown.exe' /f "%WINDIR%\explorer.exe"' (with hidden window)
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\dxdiag.exe"' (with hidden window)
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\mspaint.exe"' (with hidden window)
- '<SYSTEM32>\icacls.exe' "%WINDIR%\regedit.exe" /grant "nppetaa\user:(F)" /t' (with hidden window)
- '<SYSTEM32>\takeown.exe' /f "%WINDIR%\notepad.exe"' (with hidden window)
- '<SYSTEM32>\icacls.exe' "%WINDIR%\notepad.exe" /grant "nppetaa\user:(F)" /t' (with hidden window)
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\resmon.exe"' (with hidden window)
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\resmon.exe" /grant "nppetaa\user:(F)" /t' (with hidden window)
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\perfmon.exe"' (with hidden window)
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\perfmon.exe" /grant "nppetaa\user:(F)" /t' (with hidden window)
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\calc.exe"' (with hidden window)
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\calc.exe" /grant "nppetaa\user:(F)" /t' (with hidden window)
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\notepad.exe"' (with hidden window)
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\notepad.exe" /grant "nppetaa\user:(F)" /t' (with hidden window)
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\taskmgr.exe"' (with hidden window)
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\taskmgr.exe" /grant "nppetaa\user:(F)" /t' (with hidden window)
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\sethc.exe"' (with hidden window)
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\sethc.exe" /grant "nppetaa\user:(F)" /t' (with hidden window)
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\mmc.exe"' (with hidden window)
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\mmc.exe" /grant "nppetaa\user:(F)" /t' (with hidden window)
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\Narrator.exe"' (with hidden window)
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\Narrator.exe" /grant "nppetaa\user:(F)" /t' (with hidden window)
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\mspaint.exe" /grant "nppetaa\user:(F)" /t' (with hidden window)
- '<SYSTEM32>\icacls.exe' "%WINDIR%\explorer.exe" /grant "nppetaa\user:(F)" /t' (with hidden window)
- '<SYSTEM32>\takeown.exe' /f "%WINDIR%\regedit.exe"
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\regedt32.exe" /grant "nppetaa\user:(F)" /t
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\dism.exe"
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\dism.exe" /grant "nppetaa\user:(F)" /t
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\sfc.exe"
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\sfc.exe" /grant "nppetaa\user:(F)" /t
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\sfc.dll"
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\sfc.dll" /grant "nppetaa\user:(F)" /t
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\taskschd.msc"
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\taskschd.msc" /grant "nppetaa\user:(F)" /t
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\services.msc" /grant "nppetaa\user:(F)" /t
- '<SYSTEM32>\icacls.exe' "%WINDIR%\explorer.exe" /grant "nppetaa\user:(F)" /t
- '%WINDIR%\explorer.exe'
- '<SYSTEM32>\takeown.exe' /f "%ProgramFiles%\Windows Defender" /r /d n
- '<SYSTEM32>\icacls.exe' "%ProgramFiles%\Windows Defender" /grant "nppetaa\user:(F)" /t
- '<SYSTEM32>\takeown.exe' /f "%ProgramFiles(x86)%\Windows Defender" /r /d n
- '<SYSTEM32>\icacls.exe' "%ProgramFiles(x86)%\Windows Defender" /grant "nppetaa\user:(F)" /t
- '<SYSTEM32>\takeown.exe' /f "%ALLUSERSPROFILE%\Microsoft\Windows Defender" /r /d n
- '<SYSTEM32>\icacls.exe' "%ALLUSERSPROFILE%\Microsoft\Windows Defender" /grant "nppetaa\user:(F)" /t
- '<SYSTEM32>\takeown.exe' /f "%WINDIR%\explorer.exe"
- '<SYSTEM32>\shutdown.exe' /r /t 00 /f
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\regedt32.exe"
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\services.msc"
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\dxdiag.exe" /grant "nppetaa\user:(F)" /t
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\notepad.exe"
- '<SYSTEM32>\icacls.exe' "%WINDIR%\regedit.exe" /grant "nppetaa\user:(F)" /t
- '<SYSTEM32>\takeown.exe' /f "%WINDIR%\notepad.exe"
- '<SYSTEM32>\icacls.exe' "%WINDIR%\notepad.exe" /grant "nppetaa\user:(F)" /t
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\resmon.exe"
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\resmon.exe" /grant "nppetaa\user:(F)" /t
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\perfmon.exe"
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\perfmon.exe" /grant "nppetaa\user:(F)" /t
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\calc.exe"
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\calc.exe" /grant "nppetaa\user:(F)" /t
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\notepad.exe" /grant "nppetaa\user:(F)" /t
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\mspaint.exe" /grant "nppetaa\user:(F)" /t
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\taskmgr.exe"
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\taskmgr.exe" /grant "nppetaa\user:(F)" /t
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\sethc.exe"
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\sethc.exe" /grant "nppetaa\user:(F)" /t
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\mmc.exe"
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\mmc.exe" /grant "nppetaa\user:(F)" /t
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\Narrator.exe"
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\Narrator.exe" /grant "nppetaa\user:(F)" /t
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\mspaint.exe"
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\dxdiag.exe"
- '<SYSTEM32>\shutdown.exe' /r /t 10 /f