Technical Information
- %HOMEPATH%\Start Menu\Programs\Startup\ncjcei.org.url
- <SYSTEM32>\svchost.exe
- %HOMEPATH%\My Documents\xf-adsk2017_x64.exe
- %ALLUSERSPROFILE%\Application Data\ncjcei\ncjcei.exe
- <SYSTEM32>\.Identifier
- <SYSTEM32>\.Identifier
- '13#.#9.176.119':56565
- '<SYSTEM32>\svchost.exe'