Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'AudioClient' = ''
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Protected' = '%APPDATA%\Protected.exe'
- %HOMEPATH%\Start Menu\Programs\Startup\Protected.lnk
- %TEMP%\Protected.vbs
- %APPDATA%\Protected.exe
- %TEMP%\Protected.vbs
- '88.##0.189.114':9982
- '<Full path to file>'
- '<SYSTEM32>\wscript.exe' "%TEMP%\Protected.vbs"
- '<SYSTEM32>\reg.exe' add "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "Protected" /t REG_SZ /d "%APPDATA%\Protected.exe" /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "Protected" /t REG_SZ /d "%APPDATA%\Protected.exe" /f & exit