Technical Information
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'SystemDataSync_8ef96dcf' = '"%LOCALAPPDATA%\SystemMonitoring\DataSyncHost.exe"'
- '<Full path to file>' (downloaded from the Internet)
- %LOCALAPPDATA%\tcwnw\nbgtpasrg.exe
- %LOCALAPPDATA%\systemmonitoring\datasynchost.exe
- '17#.#6.152.62':5858
- http://17#.##.152.62:5858/d2a3db0fe2ac476e8ca876f8c23ba92f_miner.exe via 17#.#6.152.62
- '%LOCALAPPDATA%\tcwnw\nbgtpasrg.exe'
- '%LOCALAPPDATA%\systemmonitoring\datasynchost.exe'