Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Form1' = '%WINDIR%\system.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Jpg' = '%WINDIR%\JohnnyWalkerSetup.exe'
- '%WINDIR%\system.exe'
- '%WINDIR%\JohnnyWalkerSetup.exe'
- %WINDIR%\system.exe
- %WINDIR%\JohnnyWalkerSetup.exe
- 'tw##ter.com':443
- 'localhost':1036
- DNS ASK tw##ter.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'Indicator' WindowName: ''