Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Y550W6I4-W1O8-Y8D6-E6U5-B8X0R3E4K7S2' = '%APPDATA%\Y550W6I4-W1O8-Y8D6-E6U5-B8X0R3E4K7S2\Y550W6I4-W1O8-Y8D6-E6U5-B8X0R3E4K7S2.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'Y550W6I4-W1O8-Y8D6-E6U5-B8X0R3E4K7S2' = '%APPDATA%\Y550W6I4-W1O8-Y8D6-E6U5-B8X0R3E4K7S2\Y550W6I4-W1O8-Y8D6-E6U5-B8X0R3E4K7S2....
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\run] 'Y550W6I4-W1O8-Y8D6-E6U5-B8X0R3E4K7S2' = '%APPDATA%\Y550W6I4-W1O8-Y8D6-E6U5-B8X0R3E4K7S2\Y550W6I4-W1O8-Y8D6-...
- User Account Control (UAC)
- %WINDIR%\syswow64\notepad.exe
- iexplore.exe
- %APPDATA%\y550w6i4-w1o8-y8d6-e6u5-b8x0r3e4k7s2\y550w6i4-w1o8-y8d6-e6u5-b8x0r3e4k7s2.exe
- %APPDATA%\y550w6i4-w1o8-y8d6-e6u5-b8x0r3e4k7s2\ut
- %APPDATA%\y550w6i4-w1o8-y8d6-e6u5-b8x0r3e4k7s2\y550w6i4-w1o8-y8d6-e6u5-b8x0r3e4k7s2
- %APPDATA%\y550w6i4-w1o8-y8d6-e6u5-b8x0r3e4k7s2\y550w6i4-w1o8-y8d6-e6u5-b8x0r3e4k7s2.exe
- '79.##4.225.99':6712
- '%ProgramFiles(x86)%\internet explorer\iexplore.exe' <Full path to file>
- '%WINDIR%\syswow64\notepad.exe'