Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'BackUp2296801295' = '%APPDATA%\BackUp2296801295.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\BS2296801295] 'ImagePath' = '%TEMP%\NTFS.sys'
- '%TEMP%\tmp1.tmp.exe' -q -n "<SYSTEM32>\BOOT.dat" 256000
- %TEMP%\tmp1.tmp.exe
- <SYSTEM32>\BOOT.dat
- %TEMP%\NTFS.sys
- %APPDATA%\BackUp2296801295.exe