Technical Information
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'XWormClient' = '%APPDATA%\XWormClient.exe'
- %APPDATA%\microsoft\windows\start menu\programs\startup\xwormclient.lnk
- %WINDIR%\microsoft.net\framework\v4.0.30319\regsvcs.exe
- %TEMP%\aut2ca4.tmp
- %TEMP%\dunlop
- %TEMP%\aut2fa3.tmp
- %TEMP%\pluffer
- %APPDATA%\xwormclient.exe
- '19#.#27.246.79':2121
- '19#.#27.246.79':2121
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regsvcs.exe'