Technical Information
- [HKLM\SYSTEM\CurrentControlSet\Services\zMainBootProcess] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\zMainBootProcess] 'ImagePath' = '%APPDATA%\ctfmon.exe'
- 'zMainBootProcess' %APPDATA%\ctfmon.exe
- %APPDATA%\ctfmon.exe
- %WINDIR%\syswow64\config\systemprofile\appdata\roaming\ctfmon.exe
- %WINDIR%\syswow64\config\systemprofile\appdata\roaming\notepad.cfg
- DNS ASK go###e.com.br
- DNS ASK fh#.#o-ip.info
- '%APPDATA%\ctfmon.exe'