Technical Information
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe,"%APPDATA%\evqwevqw.exe",'
- %TEMP%\swhakexkqfhhdxqwmapgold_build_crypted.exe
- %APPDATA%\evqwevqw.exe
- '<SYSTEM32>\cmd.exe' /c timeout /T 20' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c timeout /T 20
- '<SYSTEM32>\timeout.exe' /T 20