Technical Information
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'LAN Subsystem' = '%ProgramFiles(x86)%\LAN Subsystem\lanss.exe'
- %APPDATA%\microsoft\windows\start menu\programs\startup\thumbnailextractionhost.url
- %WINDIR%\microsoft.net\framework\v2.0.50727\msbuild.exe
- %HOMEPATH%\thumbnailextractionhost\thumbnailextractionhost.vbs
- %HOMEPATH%\thumbnailextractionhost\forfiles.exe
- %APPDATA%\0cb67e2f-dc95-45ca-8fb8-69bde8e3f814\run.dat
- %ProgramFiles(x86)%\lan subsystem\lanss.exe
- DNS ASK an#####cmotor.ddns.net
- '%WINDIR%\microsoft.net\framework\v2.0.50727\msbuild.exe'