Technical Information
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\] 'mstwain32' = '%APPDATA%\mstwain32.exe'
- User Account Control (UAC)
- Handler for all processes: %APPDATA%\ntdtcstp.dll
- %APPDATA%\mstwain32.exe
- %APPDATA%\ntdtcstp.dll
- %APPDATA%\cmsetac.dll
- %LOCALAPPDATA%\microsoft\windows\actioncentercache\windows-systemtoast-securityandmaintenance_10_0.png
- '<LOCALNET>.1.3':15963
- '%APPDATA%\mstwain32.exe'
- '%APPDATA%\mstwain32.exe' ' (with hidden window)