Technical Information
- [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = '"%WINDIR%\SysWow64\xntjw.exe" /shell'
- %WINDIR%\syswow64\explorer.exe
- iexplore.exe
- %WINDIR%\syswow64\xntjw.exe
- '34.##9.100.209':443
- DNS ASK te#####lectrorealm.org
- '%WINDIR%\syswow64\explorer.exe' "/executable"