Technical Information
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'TEAC' = '<Full path to file>'
- C:\teac\dt\user1.w
- C:\teac\dt\dsnuitatht_user.tmp
- C:\teac\dt\user1.k
- ClassName: '' WindowName: 'KMBT_ACTTSSr'
- ClassName: '' WindowName: 'KMBT_ACTTSSl'
- ClassName: '' WindowName: 'KMBT_ACTTSSs'
- ClassName: '' WindowName: 'KMBT_ACT'
- ClassName: '' WindowName: 'User_Idle'
- ClassName: '' WindowName: 'KM_teac'
- ClassName: '' WindowName: 'WTMBT_ACT'
- '<SYSTEM32>\netsh.exe' wlan show interfaces
- '<Full path to file>' kbhook' (with hidden window)