Technical Information
- '%APPDATA%\RegConf.exe'
- '%APPDATA%\winsnrnr.exe'
- '%APPDATA%\RegConf.exe' (downloaded from the Internet)
- '<SYSTEM32>\schtasks.exe' /create /sc onlogon /f /tn winspot /rl highest /tr "%APPDATA%\winsnrnr.exe"
- '<SYSTEM32>\cmd.exe' /c ""%APPDATA%\strtpbtfile.bat" "
- chrome.exe
- %APPDATA%\RegConf.exe
- %APPDATA%\strtpbtfile.bat
- %APPDATA%\winsnrnr.exe
- %APPDATA%\strtpbtfile.bat
- %APPDATA%\winsnrnr.exe
- 'ba####demaix.com':80
- 'localhost':1038
- http://ba####demaix.com/update.exe
- DNS ASK ba####demaix.com