Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'AcroRd32.exe' = '%APPDATA%\Adobe (x86)\AcroRd32.exe'
- 'C:\Documents\btc.exe'
- '<LS_APPDATA>\Google (x86)\Chrome32.exe' C:\Documents\btc.exe
- '<SYSTEM32>\cmd.exe' /c ""%APPDATA%\btc.bat" "
- '%APPDATA%\btc.sfx.exe' -p123456780 -d%APPDATA%
- %APPDATA%\Adobe (x86)\AcroRd32.exe
- <LS_APPDATA>\Google (x86)\Chrome32.exe
- C:\Documents\btc.exe
- %APPDATA%\btc.bat
- %APPDATA%\btc.sfx.exe
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''