Persistant fileless malware that simply wont go away - Virus, Trojan, Spyware, and Malware Removal Help
Common Information
Type Value
UUID c74e6144-b063-4255-8178-a5cb99149dd7
Fingerprint cd9c185410fd9874
Analysis status DONE
Considered CTI value 0
Text language
Published Nov. 16, 2023, 7:35 a.m.
Added to db Nov. 19, 2023, 10:20 p.m.
Last updated Nov. 8, 2024, 10:23 p.m.
Headline Persistant fileless malware that simply wont go away
Title Persistant fileless malware that simply wont go away - Virus, Trojan, Spyware, and Malware Removal Help
Detected Hints/Tags/Attributes 38/1/21
Attributes
Details Type #Events CTI Value
Details File 9
%systemroot%\system32\musnotification.exe
Details File 105
bcdedit.exe
Details File 2
c:\exportbcdfile bcdedit.exe
Details File 22
dism.exe
Details File 243
autorun.inf
Details File 1
item.ps
Details File 5
%windir%\system32\lodctr.exe
Details File 5
%windir%\syswow64\lodctr.exe
Details File 4
c:\windows\syswow64\lodctr.exe
Details File 3
c:\windows\system32\lodctr.exe
Details File 3
c:\resettcpip.txt
Details Windows Registry Key 15
HKLM\SOFTWARE\Policies\Mozilla\Firefox
Details Windows Registry Key 1
HKU\S-1-5-21-3543571521-1358257338-1659789589-1001_Classes\CLSID
Details Windows Registry Key 3
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CrashControl
Details Windows Registry Key 2
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
Details Windows Registry Key 17
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
Details Windows Registry Key 26
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
Details Windows Registry Key 104
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
Details Windows Registry Key 19
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session
Details Windows Registry Key 22
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows
Details Windows Registry Key 44
HKLM\SOFTWARE\Policies\Microsoft\Windows