Technical Information
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'SHELL' = 'EXPLORER.EXE,"<Full path to file>"'
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe'
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe' /logtoconsole=false /logfile= /u "<Full path to file>"
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
- %APPDATA%\Imminent\Logs\03-08-2017
- %TEMP%\14664110.lbb4gyrwVia.docx
- %APPDATA%\PILrefFolder\PILrefFile.COM
- %APPDATA%\PILrefFolder\PILrefFile.COM
- %APPDATA%\PILrefFolder\PILrefFile.COM
- 'tr#####skay.camdvr.org':9630
- DNS ASK tr#####skay.camdvr.org