Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'BC7E4D5D3063467992E4AFA8766FF919' = '"<Full path to file>"'
- User Account Control (UAC)
- %WINDIR%\microsoft.net\framework64\v4.0.30319\jsc.exe
- %WINDIR%\microsoft.net\framework64\v4.0.30319\ngen.exe
- %WINDIR%\microsoft.net\framework64\v4.0.30319\aspnet_regsql.exe
- %WINDIR%\microsoft.net\framework64\v4.0.30319\microsoft.workflow.compiler.exe
- %WINDIR%\microsoft.net\framework64\v4.0.30319\regtlibv12.exe
- %WINDIR%\microsoft.net\framework64\v4.0.30319\edmgen.exe
- %ALLUSERSPROFILE%\remcos\logs.dat
- %ALLUSERSPROFILE%\remcos\logs.dat
- 'localhost':1235
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath "<Full path to file>" -Force' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath "<Full path to file>" -Force
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\jsc.exe'