Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Graphics' = '"%PROGRAMDATA%\Graphics\guifx.exe" /run'
- %PROGRAMDATA%\graphics\guifx.exe
- 'localhost':443
- '%PROGRAMDATA%\graphics\guifx.exe' /run
- '%PROGRAMDATA%\graphics\guifx.exe' /run' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c del /q "<Full path to file>" >> NUL' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c del /q "<Full path to file>" >> NUL