Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'e9d83924d08786ca2e4d09a73496ec88' = '"%APPDATA%\msconfig.exe" ..'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'e9d83924d08786ca2e4d09a73496ec88' = '"%APPDATA%\msconfig.exe" ..'
- %APPDATA%\microsoft\windows\start menu\programs\startup\e9d83924d08786ca2e4d09a73496ec88.exe
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%APPDATA%\msconfig.exe" "msconfig.exe" ENABLE
- %TEMP%\rarsfx0\hacker pb v5.2.exe
- %TEMP%\rarsfx0\pb.exe
- %APPDATA%\msconfig.exe
- 'n1#.#o-ip.org':1177
- DNS ASK n1#.#o-ip.org
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\rarsfx0\pb.exe'
- '%APPDATA%\msconfig.exe'
- '%TEMP%\rarsfx0\hacker pb v5.2.exe'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%APPDATA%\msconfig.exe" "msconfig.exe" ENABLE' (with hidden window)