Technical Information
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '<SYSTEM32>\explore.exe' = '<SYSTEM32>\explore.exe'
- [<HKLM>\Software\Classes\txtfile\shell\open\command] '' = '%WINDIR%\SysWow64\explore.exe'
- Windows Task Manager (Taskmgr)
- Registry Editor (RegEdit)
- %WINDIR%\syswow64\explore.exe
- %HOMEPATH%\desktop\185.exe
- %HOMEPATH%\desktop\181.exe
- %HOMEPATH%\desktop\17e.exe
- %HOMEPATH%\desktop\17b.exe
- %HOMEPATH%\desktop\177.exe
- %HOMEPATH%\desktop\174.exe
- %HOMEPATH%\desktop\171.exe
- %HOMEPATH%\desktop\16e.exe
- %HOMEPATH%\desktop\16a.exe
- %HOMEPATH%\desktop\167.exe
- %HOMEPATH%\desktop\164.exe
- %HOMEPATH%\desktop\161.exe
- %HOMEPATH%\desktop\15d.exe
- %HOMEPATH%\desktop\188.exe
- %HOMEPATH%\desktop\15a.exe
- %HOMEPATH%\desktop\154.exe
- %HOMEPATH%\desktop\150.exe
- %HOMEPATH%\desktop\14d.exe
- %HOMEPATH%\desktop\14a.exe
- %HOMEPATH%\desktop\146.exe
- %HOMEPATH%\desktop\143.exe
- %HOMEPATH%\desktop\140.exe
- %HOMEPATH%\desktop\13d.exe
- %HOMEPATH%\desktop\139.exe
- %HOMEPATH%\desktop\136.exe
- %HOMEPATH%\desktop\133.exe
- %HOMEPATH%\desktop\130.exe
- %HOMEPATH%\desktop\12c.exe
- %HOMEPATH%\desktop\157.exe
- %HOMEPATH%\desktop\18b.exe
- 'i0.##slb.com':443
- 'microsoft.com':80
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- 'i0.##slb.com':443
- DNS ASK i0.##slb.com
- DNS ASK microsoft.com