Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\bthtelemetry.url
- %WINDIR%\syswow64\dllhost.exe
- %WINDIR%\syswow64\svchost.exe
- %HOMEPATH%\bthtelemetry\bthtelemetry.vbs
- %HOMEPATH%\bthtelemetry\msra.exe
- %APPDATA%\remcos\logs.dat
- %APPDATA%\remcos\logs.dat
- '18#.#40.53.154':8760
- '%WINDIR%\syswow64\dllhost.exe'
- '%WINDIR%\syswow64\svchost.exe'