Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '' = '%TEMP%\Email hacker.exe'
- Windows Task Manager (Taskmgr)
- Registry Editor (RegEdit)
- '<LS_APPDATA>\Xenocode\Sandbox\AVAST\7.8.9\2013.07.15T02.15\Native\STUBEXE\@PROFILE@\Local Settings\Temp\Email hacker.exe'
- '<LS_APPDATA>\Xenocode\Sandbox\AVAST\7.8.9\2013.07.15T02.15\Virtual\STUBEXE\@APPDIR@\facebook+ Email hacker.exe'
- Handler for the 'Email hacker.exe' process: %TEMP%\Email hacker.exe
- outpost.exe
- AVP.EXE
- bdagent.exe
- %TEMP%\Email hacker.exe
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'Indicator' WindowName: '(null)'