Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'TFM0N' = 'c:\uv12mldeqp1ldq7q\Aesyt.exe'
- C:\uv12mldeqp1ldq7q\setting.xml
- from <Full path to virus> to C:\uv12mldeqp1ldq7q\Aesyt.exe
- '19#.#4.252.39':8760
- '19#.#4.252.40':806
- ClassName: 'Indicator' WindowName: ''