Technical Information
- [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe,"%APPDATA%\msbuidd.exe",'
- '' (downloaded from the Internet)
- 'C:\users\public\vbc.exe'
- %WINDIR%\explorer.exe
- vbc.exe
- C:\users\public\vbc.exe
- %APPDATA%\msbuidd.exe
- '14#.#4.148.33':80
- http://14#.#4.148.33/vvx/INV.exe
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -ENC cwB0AGEAcgB0AC0AcwBsAGUAZQBwACAALQBzAGUAYwBvAG4AZABzACAAMQA1AA==' (with hidden window)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -ENC cwB0AGEAcgB0AC0AcwBsAGUAZQBwACAALQBzAGUAYwBvAG4AZABzACAAMQA1AA==
- '%WINDIR%\syswow64\cmmon32.exe'