Technical Information
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'shell' = 'explorer.exe, %APPDATA%\d96232e0\eudcedit.exe'
- '<SYSTEM32>\svchost.exe'
- '<SYSTEM32>\schtasks.exe' /Create /TN "JPCRAW\JPCRAW" /XML "%APPDATA%\JPCRAW\aRRRRR.xml"
- <SYSTEM32>\svchost.exe
- %APPDATA%\d96232e0\eudcedit.exe
- %APPDATA%\JPCRAW\aRRRRR.xml
- %APPDATA%\JPCRAW\JPCRAW.exe
- %APPDATA%\JPCRAW\aRRRRR.xml
- '18#.#53.231.44':80