Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'VersionRecover' = '%LOCALAPPDATA%\Microsoft\spoolsvc.exe'
- [<HKLM>\System\CurrentControlSet\Services\EFS] 'Start' = '00000002'
- nul
- %APPDATA%\fix.exe
- http://be#####eenshottool.su/downloads/Build.dll
- http://fa###rtf.best/fixd.exe
- DNS ASK be#####eenshottool.su
- DNS ASK fa###rtf.best
- '%LOCALAPPDATA%\microsoft\spoolsvc.exe'
- '%APPDATA%\fix.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ping 1.1.1.1 -n 1 -w 1000 >nul & del "<Full path to file>"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ping 1.1.1.1 -n 1 -w 1000 >nul & del "<Full path to file>"
- '%WINDIR%\syswow64\ping.exe' 1.1.1.1 -n 1 -w 1000