Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'svhost2' = '%APPDATA%\apps.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'svhost' = '%TEMP%\svhost.vbs'
- %HOMEPATH%\Start Menu\Programs\Startup\svhost.lnk
- %TEMP%\ReesterCreate.vbs
- %TEMP%\svhost.vbs
- %TEMP%\msvcr110.dll
- %TEMP%\start.bat
- %TEMP%\svhost.exe
- %TEMP%\ReesterCreate.vbs
- %TEMP%\svhost.vbs
- %TEMP%\msvcr110.dll
- %TEMP%\start.bat
- %TEMP%\svhost.exe
- ClassName: 'EDIT' WindowName: ''
- '<SYSTEM32>\wscript.exe' "%TEMP%\ReesterCreate.vbs"
- '<SYSTEM32>\wscript.exe' "%TEMP%\svhost.vbs"
- '<SYSTEM32>\netsh.exe' Advfirewall set allprofiles state off
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\start.bat" "