Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'xw' = '%ALLUSERSPROFILE%\Start Menu\Programs\start.exe'
- %HOMEPATH%\Start Menu\Programs\Startup\1tXp5k3s7y.eu.url
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe'
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
- %TEMP%\4TjopRwQF.TG
- %APPDATA%\Monitor\Screenshots\11-11-2017\4.55 AM
- %TEMP%\aut1.tmp
- %APPDATA%\1tXp5k3s7y\1tXp5k3s7y.exe
- %ALLUSERSPROFILE%\Start Menu\Programs\start.exe
- %TEMP%\aut1.tmp
- '18#.#66.236.103':18342