Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Form1' = '%WINDIR%\system.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Jpg' = '<Full path to virus>'
- '%WINDIR%\system.exe'
- %WINDIR%\system.exe
- 'tw##ter.com':443
- 'localhost':1037
- DNS ASK tw##ter.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'Indicator' WindowName: ''