Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'HOST PROCESS FOR WINDOWS TASKS' = '%APPDATA%\Microsoft\taskhostw.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'HOST PROCESS FOR WINDOWS TASKS' = '%APPDATA%\Microsoft\taskhostw.exe'
- %APPDATA%\microsoft\taskhostw.exe
- %APPDATA%\microsoft\taskhostw.exe
- http://54.##.199.55/join/client.php?st##################################################
- '%APPDATA%\microsoft\taskhostw.exe'