Technical Information
- <SYSTEM32>\tasks\advancedsystemrepairpro-maintenance-autorun
- [<HKLM>\SYSTEM\CurrentControlSet\services\asrdmon] 'ImagePath' = '<DRIVERS>\asrdmon.sys'
- [<HKLM>\SYSTEM\CurrentControlSet\services\asrdmon] 'Start' = '00000001'
- [<HKLM>\System\CurrentControlSet\Services\asrrealtimesrv] 'ImagePath' = '%ProgramFiles(x86)%\Advanced System Repair Pro 1.9.2.8.0\asrrealtimesrv.exe'
- [<HKLM>\System\CurrentControlSet\Services\wuauserv] 'Start' = '00000002'
- 'asrdmon' <DRIVERS>\asrdmon.sys
- 'asrrealtimesrv' %ProgramFiles(x86)%\Advanced System Repair Pro 1.9.2.8.0\asrrealtimesrv.exe
- [<HKLM>\SYSTEM\CurrentControlSet\services\asrdmon] 'Group' = 'FSFilter Content Screener'
- %PROGRAMDATA%\tsr7settings\s3.txt
- %APPDATA%\microsoft\windows\start menu\programs\advanced system repair pro\uninstall advanced system repair pro.lnk
- C:\users\public\desktop\advanced system repair pro.lnk
- %PROGRAMDATA%\tsr7settings\uninstasr.exe
- %WINDIR%\temp\udd7167.tmp
- %WINDIR%\temp\udd7d3f.tmp
- %ProgramFiles(x86)%\advanced system repair pro 1.9.2.8.0\pcw.dll
- %PROGRAMDATA%\tsr7settings\srv.db-journal
- %PROGRAMDATA%\tsr7settings\srv.db
- %ProgramFiles(x86)%\advanced system repair pro 1.9.2.8.0\system.security.cryptography.algorithms.dll
- %PROGRAMDATA%\tsr7settings\srv.log
- %WINDIR%\temp\udd9f8f.tmp
- %PROGRAMDATA%\tsr7settings\st.db-journal
- %PROGRAMDATA%\tsr7settings\st.db
- %PROGRAMDATA%\tsr7settings\app.log
- %PROGRAMDATA%\tsr7settings\1.dat.tmp
- %PROGRAMDATA%\tsr7settings\res2.db-journal
- %PROGRAMDATA%\tsr7settings\res2.db
- %PROGRAMDATA%\tsr7settings\res2.db-shm
- %APPDATA%\microsoft\windows\start menu\programs\advanced system repair pro\advanced system repair pro.lnk
- %TEMP%\pctskbr4.vbs
- %WINDIR%\temp\udd4f09.tmp
- %WINDIR%\temp\udd40b0.tmp
- <DRIVERS>\asrdmon.sys
- %ProgramFiles(x86)%\advanced system repair pro 1.9.2.8.0\advancedsystemrepairpro.exe
- %ProgramFiles(x86)%\advanced system repair pro 1.9.2.8.0\asrscan.sys
- %ProgramFiles(x86)%\advanced system repair pro 1.9.2.8.0\bouncycastle.crypto.dll
- %ProgramFiles(x86)%\advanced system repair pro 1.9.2.8.0\dsutil.exe
- %ProgramFiles(x86)%\advanced system repair pro 1.9.2.8.0\infextractor.dll
- %ProgramFiles(x86)%\advanced system repair pro 1.9.2.8.0\microsoft.deployment.windowsinstaller.dll
- %ProgramFiles(x86)%\advanced system repair pro 1.9.2.8.0\microsoft.experimental.io.dll
- %ProgramFiles(x86)%\advanced system repair pro 1.9.2.8.0\newtonsoft.json.dll
- %PROGRAMDATA%\tsr7settings\res2.db-wal
- %WINDIR%\temp\udd8520.tmp
- %ProgramFiles(x86)%\advanced system repair pro 1.9.2.8.0\sevenzipsharp.dll
- %ProgramFiles(x86)%\advanced system repair pro 1.9.2.8.0\system.security.cryptography.primitives.dll
- %ProgramFiles(x86)%\advanced system repair pro 1.9.2.8.0\system.security.cryptography.x509certificates.dll
- %ProgramFiles(x86)%\advanced system repair pro 1.9.2.8.0\zetalongpaths.dll
- %ProgramFiles(x86)%\advanced system repair pro 1.9.2.8.0\7z\7z.dll
- %ProgramFiles(x86)%\advanced system repair pro 1.9.2.8.0\7z\7z.exe
- %ProgramFiles(x86)%\advanced system repair pro 1.9.2.8.0\7z\license.txt
- %ProgramFiles(x86)%\advanced system repair pro 1.9.2.8.0\pcw.pack
- %ProgramFiles(x86)%\advanced system repair pro 1.9.2.8.0\asrrealtimesrv.exe
- %TEMP%\pctskbr5.vbs
- %ProgramFiles(x86)%\advanced system repair pro 1.9.2.8.0\system.security.cryptography.encoding.dll
- %PROGRAMDATA%\tsr7settings\e.txt
- %WINDIR%\temp\udd40b0.tmp
- %WINDIR%\temp\udd4f09.tmp
- %WINDIR%\temp\udd7167.tmp
- %PROGRAMDATA%\tsr7settings\srv.db-journal
- %WINDIR%\temp\udd7d3f.tmp
- %WINDIR%\temp\udd8520.tmp
- %WINDIR%\temp\udd9f8f.tmp
- %PROGRAMDATA%\tsr7settings\st.db-journal
- %PROGRAMDATA%\tsr7settings\res2.db-journal
- from %PROGRAMDATA%\tsr7settings\1.dat.tmp to %PROGRAMDATA%\tsr7settings\1.dat
- %PROGRAMDATA%\tsr7settings\st.db-journal
- http://as###dates.com/db5/1.dat
- http://as###dates.com/al.php
- http://as###dates.com/app_upgrade/asr.php?a=##################################
- http://as###dates.com/pui/pui.php
- DNS ASK as###dates.com
- ClassName: '' WindowName: 'Advanced System Repair Pro App'
- '%WINDIR%\syswow64\wscript.exe' //B //T:10 "%TEMP%\pctskbr5.vbs"
- '%ProgramFiles(x86)%\advanced system repair pro 1.9.2.8.0\asrrealtimesrv.exe' -install yes
- '%WINDIR%\syswow64\wscript.exe' //B //T:10 "%TEMP%\pctskbr4.vbs"
- '%ProgramFiles(x86)%\advanced system repair pro 1.9.2.8.0\asrrealtimesrv.exe'
- '%ProgramFiles(x86)%\advanced system repair pro 1.9.2.8.0\advancedsystemrepairpro.exe' /postupdate
- '%ProgramFiles(x86)%\advanced system repair pro 1.9.2.8.0\dsutil.exe'
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\mfc140cht.dll' (with hidden window)
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\mfcm140u.dll' (with hidden window)
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\mfc140enu.dll' (with hidden window)
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\mfc140u.dll' (with hidden window)
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\mfcm140.dll' (with hidden window)
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\mfc140ita.dll' (with hidden window)
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\mfc140jpn.dll' (with hidden window)
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\mfc140rus.dll' (with hidden window)
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\mfc140fra.dll' (with hidden window)
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\mfc140esn.dll' (with hidden window)
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\mfc140kor.dll' (with hidden window)
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\msvcp140.dll' (with hidden window)
- '%WINDIR%\syswow64\wscript.exe' //B //T:10 "%TEMP%\pctskbr5.vbs"' (with hidden window)
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\msvcp140d.dll' (with hidden window)
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\mfc140deu.dll' (with hidden window)
- '%WINDIR%\syswow64\wscript.exe' //B //T:10 "%TEMP%\pctskbr4.vbs"' (with hidden window)
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\mfc140chs.dll' (with hidden window)
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\concrt140d.dll' (with hidden window)
- '%ProgramFiles(x86)%\advanced system repair pro 1.9.2.8.0\dsutil.exe' ' (with hidden window)
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\vccorlib140d.dll' (with hidden window)
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\vcruntime140d.dll' (with hidden window)
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\ucrtbased.dll' (with hidden window)
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\concrt140.dll' (with hidden window)
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\vcamp140.dll' (with hidden window)
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\mfc140.dll' (with hidden window)
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\vccorlib140.dll' (with hidden window)
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\concrt140d.dll
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\msvcp140.dll
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\mfcm140u.dll
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\mfcm140.dll
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\mfc140u.dll
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\mfc140rus.dll
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\mfc140kor.dll
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\mfc140jpn.dll
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\mfc140ita.dll
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\mfc140fra.dll
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\vcamp140.dll
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\mfc140esn.dll
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\mfc140deu.dll
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\mfc140cht.dll
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\mfc140chs.dll
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\mfc140.dll
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\concrt140.dll
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\ucrtbased.dll
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\vcruntime140d.dll
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\vccorlib140d.dll
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\msvcp140d.dll
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\mfc140enu.dll
- '<SYSTEM32>\sfc.exe' /VERIFYFILE=<SYSTEM32>\vccorlib140.dll