Technical Information
- [<HKLM>\System\CurrentControlSet\Services\pstorec] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\pstorec] 'ImagePath' = '"%WINDIR%\SysWOW64\NlsLexicons0021\pstorec.exe"'
- 'pstorec' "%WINDIR%\SysWOW64\NlsLexicons0021\pstorec.exe"
- 'pstorec' %WINDIR%\SysWOW64\NlsLexicons0021\pstorec.exe
- from <Full path to file> to %WINDIR%\syswow64\nlslexicons0021\pstorec.exe
- '68.##.137.144':443
- '69.##.203.214':8080
- http://69.##.203.214:8080/upIgb6it2bK39/q6vbqRnaUGx0F1/n5zEW/7DAYcJPsjQ1/8hSLF93P0TgTaiC/vXBGSw/ via 69.##.203.214