Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'csrs.exe' = '%WINDIR%\csrs.exe'
- ClassName: 'TibiaClient', WindowName: ''
- %TEMP%\stp.exe
- %TEMP%\ctfmoon.exe
- %WINDIR%\csrs.exe
- %WINDIR%\ctfmoon1.exe
- '18#.#65.245.114':80
- http://www.ua####eylogger.pl/version.txt
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\stp.exe' -pxsw
- '%TEMP%\ctfmoon.exe'
- '%WINDIR%\ctfmoon1.exe'