Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '90b78008-cd10-4a66-a0fd-b8eba9b65289' = '%APPDATA%\nwtuo\nwtuo.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '90b78008-cd10-4a66-a0fd-b8eba9b65289' = '%APPDATA%\nwtuo\nwtuo.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Associations] 'LowRiskFileTypes' = '.exe;.bat;.reg;.vbs;'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] '1806' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] '1806' = '00000000'
- %APPDATA%\nwtuo\nwtuo.exe
- <Full path to file>
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE'