Analysis
-
max time kernel
118s -
max time network
120s -
platform
windows7_x64 -
resource
win7-20240221-en -
resource tags
arch:x64arch:x86image:win7-20240221-enlocale:en-usos:windows7-x64system -
submitted
02-07-2024 21:11
Behavioral task
behavioral1
Sample
1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe
Resource
win7-20240221-en
General
-
Target
1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe
-
Size
650KB
-
MD5
1d74fad1e7d34e01d3d775528ef60460
-
SHA1
822bc0882d94ff9b2c6396d97dd6ee7c0d0a7356
-
SHA256
0198e4ece40cebc1f98328360ca69e4b5386c2ff444596b268eb9af4ff137c97
-
SHA512
27414da752359560068dc533f53e8c58161f4739194f2bbbc8e2a3e5c9989a3e5dfa2a6c137f8465ade8611d7274da2c20bccfd880622e0484c516c8528b0d1e
-
SSDEEP
12288:bk0QVlhmPojAPTMEsUTg0oChO/Q2JbsbjPbN5qhRTtYe3f+Iw86k/9/+I:Q0QRWoJEfg0oChGdJQbjPbNW5tYeP+GB
Malware Config
Extracted
darkcomet
blowme
90.207.119.46:443
AF48NLA
-
InstallPath
\msdcsc.exe
-
gencode
roqmzCFsJnuf
-
install
true
-
offline_keylogger
true
-
password
blowmeya
-
persistence
true
-
reg_key
update
Signatures
-
Modifies WinLogon for persistence 2 TTPs 42 IoCs
Processes:
msdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exe1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exedescription ioc process Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe" 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit = "C:\\Windows\\system32\\userinit.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe,C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe -
Deletes itself 1 IoCs
Processes:
cmd.exepid process 3020 cmd.exe -
Executes dropped EXE 40 IoCs
Processes:
msdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exepid process 2064 msdcsc.exe 2568 msdcsc.exe 2456 msdcsc.exe 2476 msdcsc.exe 1432 msdcsc.exe 1780 msdcsc.exe 1720 msdcsc.exe 536 msdcsc.exe 1120 msdcsc.exe 1632 msdcsc.exe 772 msdcsc.exe 1664 msdcsc.exe 1736 msdcsc.exe 2552 msdcsc.exe 2712 msdcsc.exe 2192 msdcsc.exe 2380 msdcsc.exe 1432 msdcsc.exe 2020 msdcsc.exe 1796 msdcsc.exe 1632 msdcsc.exe 1952 msdcsc.exe 2604 msdcsc.exe 2440 msdcsc.exe 3056 msdcsc.exe 1780 msdcsc.exe 484 msdcsc.exe 2436 msdcsc.exe 2916 msdcsc.exe 2684 msdcsc.exe 2440 msdcsc.exe 2256 msdcsc.exe 1132 msdcsc.exe 2916 msdcsc.exe 1608 msdcsc.exe 800 msdcsc.exe 1792 msdcsc.exe 1976 msdcsc.exe 2276 msdcsc.exe 744 msdcsc.exe -
Loads dropped DLL 42 IoCs
Processes:
1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exepid process 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe 2064 msdcsc.exe 2064 msdcsc.exe 2568 msdcsc.exe 2568 msdcsc.exe 2456 msdcsc.exe 2476 msdcsc.exe 1432 msdcsc.exe 1780 msdcsc.exe 1720 msdcsc.exe 536 msdcsc.exe 1120 msdcsc.exe 1632 msdcsc.exe 772 msdcsc.exe 1664 msdcsc.exe 2552 msdcsc.exe 2712 msdcsc.exe 2192 msdcsc.exe 2380 msdcsc.exe 1432 msdcsc.exe 2020 msdcsc.exe 1796 msdcsc.exe 1632 msdcsc.exe 1952 msdcsc.exe 2604 msdcsc.exe 2440 msdcsc.exe 3056 msdcsc.exe 1780 msdcsc.exe 484 msdcsc.exe 2436 msdcsc.exe 2916 msdcsc.exe 2684 msdcsc.exe 2440 msdcsc.exe 2256 msdcsc.exe 1132 msdcsc.exe 2640 msdcsc.exe 1608 msdcsc.exe 800 msdcsc.exe 1792 msdcsc.exe 1976 msdcsc.exe 2276 msdcsc.exe -
Adds Run key to start application 2 TTPs 42 IoCs
Processes:
msdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exe1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exemsdcsc.exedescription ioc process Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe" 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe Set value (str) \REGISTRY\USER\S-1-5-21-2297530677-1229052932-2803917579-1000\Software\Microsoft\Windows\CurrentVersion\Run\update = "C:\\Users\\Admin\\AppData\\Roaming\\\\roqmzCFsJnuf\\msdcsc.exe" msdcsc.exe -
Enumerates physical storage devices 1 TTPs
Attempts to interact with connected storage/optical drive(s).
-
Runs ping.exe 1 TTPs 42 IoCs
Processes:
PING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEPING.EXEpid process 2020 PING.EXE 2500 PING.EXE 2292 PING.EXE 568 PING.EXE 2948 PING.EXE 1720 PING.EXE 988 PING.EXE 1796 PING.EXE 1056 PING.EXE 2252 PING.EXE 2544 PING.EXE 840 PING.EXE 1780 PING.EXE 2692 PING.EXE 2400 PING.EXE 2832 PING.EXE 1544 PING.EXE 2872 PING.EXE 2240 PING.EXE 1496 PING.EXE 2932 PING.EXE 788 PING.EXE 2268 PING.EXE 2076 PING.EXE 1640 PING.EXE 2600 PING.EXE 2604 PING.EXE 2276 PING.EXE 2072 PING.EXE 2516 PING.EXE 1452 PING.EXE 1132 PING.EXE 2348 PING.EXE 1704 PING.EXE 1460 PING.EXE 1744 PING.EXE 1168 PING.EXE 3052 PING.EXE 1580 PING.EXE 2036 PING.EXE 2200 PING.EXE 884 PING.EXE -
Suspicious use of AdjustPrivilegeToken 64 IoCs
Processes:
1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exemsdcsc.exemsdcsc.exedescription pid process Token: SeIncreaseQuotaPrivilege 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe Token: SeSecurityPrivilege 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe Token: SeTakeOwnershipPrivilege 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe Token: SeLoadDriverPrivilege 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe Token: SeSystemProfilePrivilege 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe Token: SeSystemtimePrivilege 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe Token: SeProfSingleProcessPrivilege 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe Token: SeCreatePagefilePrivilege 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe Token: SeBackupPrivilege 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe Token: SeRestorePrivilege 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe Token: SeShutdownPrivilege 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe Token: SeDebugPrivilege 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe Token: SeSystemEnvironmentPrivilege 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe Token: SeChangeNotifyPrivilege 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe Token: SeRemoteShutdownPrivilege 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe Token: SeUndockPrivilege 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe Token: SeManageVolumePrivilege 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe Token: SeImpersonatePrivilege 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe Token: SeCreateGlobalPrivilege 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe Token: 33 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe Token: 34 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe Token: 35 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe Token: SeIncreaseQuotaPrivilege 2064 msdcsc.exe Token: SeSecurityPrivilege 2064 msdcsc.exe Token: SeTakeOwnershipPrivilege 2064 msdcsc.exe Token: SeLoadDriverPrivilege 2064 msdcsc.exe Token: SeSystemProfilePrivilege 2064 msdcsc.exe Token: SeSystemtimePrivilege 2064 msdcsc.exe Token: SeProfSingleProcessPrivilege 2064 msdcsc.exe Token: SeIncBasePriorityPrivilege 2064 msdcsc.exe Token: SeCreatePagefilePrivilege 2064 msdcsc.exe Token: SeBackupPrivilege 2064 msdcsc.exe Token: SeRestorePrivilege 2064 msdcsc.exe Token: SeShutdownPrivilege 2064 msdcsc.exe Token: SeDebugPrivilege 2064 msdcsc.exe Token: SeSystemEnvironmentPrivilege 2064 msdcsc.exe Token: SeChangeNotifyPrivilege 2064 msdcsc.exe Token: SeRemoteShutdownPrivilege 2064 msdcsc.exe Token: SeUndockPrivilege 2064 msdcsc.exe Token: SeManageVolumePrivilege 2064 msdcsc.exe Token: SeImpersonatePrivilege 2064 msdcsc.exe Token: SeCreateGlobalPrivilege 2064 msdcsc.exe Token: 33 2064 msdcsc.exe Token: 34 2064 msdcsc.exe Token: 35 2064 msdcsc.exe Token: SeIncreaseQuotaPrivilege 2568 msdcsc.exe Token: SeSecurityPrivilege 2568 msdcsc.exe Token: SeTakeOwnershipPrivilege 2568 msdcsc.exe Token: SeLoadDriverPrivilege 2568 msdcsc.exe Token: SeSystemProfilePrivilege 2568 msdcsc.exe Token: SeSystemtimePrivilege 2568 msdcsc.exe Token: SeProfSingleProcessPrivilege 2568 msdcsc.exe Token: SeIncBasePriorityPrivilege 2568 msdcsc.exe Token: SeCreatePagefilePrivilege 2568 msdcsc.exe Token: SeBackupPrivilege 2568 msdcsc.exe Token: SeRestorePrivilege 2568 msdcsc.exe Token: SeShutdownPrivilege 2568 msdcsc.exe Token: SeDebugPrivilege 2568 msdcsc.exe Token: SeSystemEnvironmentPrivilege 2568 msdcsc.exe Token: SeChangeNotifyPrivilege 2568 msdcsc.exe Token: SeRemoteShutdownPrivilege 2568 msdcsc.exe Token: SeUndockPrivilege 2568 msdcsc.exe Token: SeManageVolumePrivilege 2568 msdcsc.exe -
Suspicious use of WriteProcessMemory 64 IoCs
Processes:
1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.execmd.exemsdcsc.execmd.exemsdcsc.execmd.exemsdcsc.execmd.exemsdcsc.execmd.exemsdcsc.exedescription pid process target process PID 3068 wrote to memory of 3020 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe cmd.exe PID 3068 wrote to memory of 3020 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe cmd.exe PID 3068 wrote to memory of 3020 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe cmd.exe PID 3068 wrote to memory of 3020 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe cmd.exe PID 3020 wrote to memory of 2500 3020 cmd.exe PING.EXE PID 3020 wrote to memory of 2500 3020 cmd.exe PING.EXE PID 3020 wrote to memory of 2500 3020 cmd.exe PING.EXE PID 3020 wrote to memory of 2500 3020 cmd.exe PING.EXE PID 3068 wrote to memory of 2064 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe msdcsc.exe PID 3068 wrote to memory of 2064 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe msdcsc.exe PID 3068 wrote to memory of 2064 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe msdcsc.exe PID 3068 wrote to memory of 2064 3068 1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe msdcsc.exe PID 2064 wrote to memory of 2564 2064 msdcsc.exe cmd.exe PID 2064 wrote to memory of 2564 2064 msdcsc.exe cmd.exe PID 2064 wrote to memory of 2564 2064 msdcsc.exe cmd.exe PID 2064 wrote to memory of 2564 2064 msdcsc.exe cmd.exe PID 2564 wrote to memory of 2076 2564 cmd.exe PING.EXE PID 2564 wrote to memory of 2076 2564 cmd.exe PING.EXE PID 2564 wrote to memory of 2076 2564 cmd.exe PING.EXE PID 2564 wrote to memory of 2076 2564 cmd.exe PING.EXE PID 2064 wrote to memory of 2568 2064 msdcsc.exe msdcsc.exe PID 2064 wrote to memory of 2568 2064 msdcsc.exe msdcsc.exe PID 2064 wrote to memory of 2568 2064 msdcsc.exe msdcsc.exe PID 2064 wrote to memory of 2568 2064 msdcsc.exe msdcsc.exe PID 2568 wrote to memory of 2676 2568 msdcsc.exe cmd.exe PID 2568 wrote to memory of 2676 2568 msdcsc.exe cmd.exe PID 2568 wrote to memory of 2676 2568 msdcsc.exe cmd.exe PID 2568 wrote to memory of 2676 2568 msdcsc.exe cmd.exe PID 2676 wrote to memory of 2400 2676 cmd.exe PING.EXE PID 2676 wrote to memory of 2400 2676 cmd.exe PING.EXE PID 2676 wrote to memory of 2400 2676 cmd.exe PING.EXE PID 2676 wrote to memory of 2400 2676 cmd.exe PING.EXE PID 2568 wrote to memory of 2456 2568 msdcsc.exe msdcsc.exe PID 2568 wrote to memory of 2456 2568 msdcsc.exe msdcsc.exe PID 2568 wrote to memory of 2456 2568 msdcsc.exe msdcsc.exe PID 2568 wrote to memory of 2456 2568 msdcsc.exe msdcsc.exe PID 2456 wrote to memory of 2808 2456 msdcsc.exe cmd.exe PID 2456 wrote to memory of 2808 2456 msdcsc.exe cmd.exe PID 2456 wrote to memory of 2808 2456 msdcsc.exe cmd.exe PID 2456 wrote to memory of 2808 2456 msdcsc.exe cmd.exe PID 2808 wrote to memory of 2832 2808 cmd.exe PING.EXE PID 2808 wrote to memory of 2832 2808 cmd.exe PING.EXE PID 2808 wrote to memory of 2832 2808 cmd.exe PING.EXE PID 2808 wrote to memory of 2832 2808 cmd.exe PING.EXE PID 2456 wrote to memory of 2476 2456 msdcsc.exe msdcsc.exe PID 2456 wrote to memory of 2476 2456 msdcsc.exe msdcsc.exe PID 2456 wrote to memory of 2476 2456 msdcsc.exe msdcsc.exe PID 2456 wrote to memory of 2476 2456 msdcsc.exe msdcsc.exe PID 2476 wrote to memory of 1276 2476 msdcsc.exe cmd.exe PID 2476 wrote to memory of 1276 2476 msdcsc.exe cmd.exe PID 2476 wrote to memory of 1276 2476 msdcsc.exe cmd.exe PID 2476 wrote to memory of 1276 2476 msdcsc.exe cmd.exe PID 2476 wrote to memory of 1432 2476 msdcsc.exe msdcsc.exe PID 2476 wrote to memory of 1432 2476 msdcsc.exe msdcsc.exe PID 2476 wrote to memory of 1432 2476 msdcsc.exe msdcsc.exe PID 2476 wrote to memory of 1432 2476 msdcsc.exe msdcsc.exe PID 1276 wrote to memory of 2292 1276 cmd.exe PING.EXE PID 1276 wrote to memory of 2292 1276 cmd.exe PING.EXE PID 1276 wrote to memory of 2292 1276 cmd.exe PING.EXE PID 1276 wrote to memory of 2292 1276 cmd.exe PING.EXE PID 1432 wrote to memory of 2648 1432 msdcsc.exe cmd.exe PID 1432 wrote to memory of 2648 1432 msdcsc.exe cmd.exe PID 1432 wrote to memory of 2648 1432 msdcsc.exe cmd.exe PID 1432 wrote to memory of 2648 1432 msdcsc.exe cmd.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe"1⤵
- Modifies WinLogon for persistence
- Loads dropped DLL
- Adds Run key to start application
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Local\Temp\1d74fad1e7d34e01d3d775528ef60460_JaffaCakes118.exe"2⤵
- Deletes itself
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 43⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\msdcsc.exe"C:\Users\Admin\AppData\Roaming\msdcsc.exe"2⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\msdcsc.exe"3⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 44⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"3⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"4⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 45⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"4⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"5⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 46⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"5⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"6⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 47⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"6⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"7⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 48⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"7⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"8⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 49⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"8⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"9⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 410⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"9⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"10⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 411⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"10⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"11⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 412⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"11⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"12⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 413⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"12⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"13⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 414⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"13⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"14⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 415⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"14⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"15⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 416⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"15⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"16⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 417⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"16⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"17⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 418⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"17⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"18⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 419⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"18⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"19⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 420⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"19⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"20⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 421⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"20⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"21⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 422⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"21⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"22⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 423⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"22⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"23⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 424⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"23⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"24⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 425⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"24⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"25⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 426⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"25⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"26⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 427⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"26⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"27⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 428⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"27⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"28⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 429⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"28⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"29⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 430⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"29⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"30⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 431⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"30⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"31⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 432⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"31⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"32⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 433⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"32⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"33⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 434⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"33⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"34⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 435⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"34⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"35⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 436⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"35⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"36⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 437⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\msdcsc.exe"C:\Users\Admin\AppData\Roaming\msdcsc.exe"36⤵
- Modifies WinLogon for persistence
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\msdcsc.exe"37⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 438⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"37⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"38⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 439⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"38⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"39⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 440⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"39⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"40⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 441⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"40⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\roqmzCFsJnuf\msdcsc.exe"41⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 442⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\msdcsc.exe"C:\Users\Admin\AppData\Roaming\msdcsc.exe"41⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Loads dropped DLL
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\msdcsc.exe"42⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 443⤵
- Runs ping.exe
-
C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"42⤵
- Modifies WinLogon for persistence
- Executes dropped EXE
- Adds Run key to start application
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /k ping 127.0.0.1 -n 4 && del "C:\Users\Admin\AppData\Roaming\roqmzCFsJnuf\msdcsc.exe"43⤵
-
C:\Windows\SysWOW64\PING.EXEping 127.0.0.1 -n 444⤵
- Runs ping.exe
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
\Users\Admin\AppData\Roaming\msdcsc.exeFilesize
650KB
MD51d74fad1e7d34e01d3d775528ef60460
SHA1822bc0882d94ff9b2c6396d97dd6ee7c0d0a7356
SHA2560198e4ece40cebc1f98328360ca69e4b5386c2ff444596b268eb9af4ff137c97
SHA51227414da752359560068dc533f53e8c58161f4739194f2bbbc8e2a3e5c9989a3e5dfa2a6c137f8465ade8611d7274da2c20bccfd880622e0484c516c8528b0d1e
-
memory/484-257-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/536-95-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/744-343-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/772-124-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/800-319-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/1120-105-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/1132-295-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/1432-186-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/1432-65-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/1608-312-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/1632-114-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/1632-215-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/1664-134-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/1720-84-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/1736-138-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/1780-74-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/1780-250-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/1792-326-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/1796-207-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/1952-222-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/1976-333-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/2020-196-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/2064-23-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/2192-167-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/2256-288-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/2276-340-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/2380-177-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/2436-264-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/2440-236-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/2440-281-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/2456-45-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/2476-54-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/2552-146-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/2568-35-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/2604-229-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/2640-305-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/2684-274-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/2712-156-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/2916-298-0x00000000777D0000-0x00000000778CA000-memory.dmpFilesize
1000KB
-
memory/2916-296-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/2916-297-0x00000000778D0000-0x00000000779EF000-memory.dmpFilesize
1.1MB
-
memory/2916-267-0x00000000777D0000-0x00000000778CA000-memory.dmpFilesize
1000KB
-
memory/2916-265-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/2916-266-0x00000000778D0000-0x00000000779EF000-memory.dmpFilesize
1.1MB
-
memory/3056-243-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB
-
memory/3068-0-0x0000000000270000-0x0000000000271000-memory.dmpFilesize
4KB
-
memory/3068-11-0x0000000000400000-0x00000000004B0000-memory.dmpFilesize
704KB