Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'AppRt39df' = '%LOCALAPPDATA%\AppRt39df\apprt39df.exe'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'AppSvc39df' = '%LOCALAPPDATA%\Programs\39df\svc39df.exe'
- nul
- %LOCALAPPDATA%\apprt39df\apprt39df.exe
- %LOCALAPPDATA%\programs\39df\svc39df.exe
- '20#.#94.54.131':6543
- '%LOCALAPPDATA%\apprt39df\apprt39df.exe'
- '%LOCALAPPDATA%\programs\39df\svc39df.exe'
- '%LOCALAPPDATA%\apprt39df\apprt39df.exe' ' (with hidden window)
- '%LOCALAPPDATA%\programs\39df\svc39df.exe' ' (with hidden window)