Technical Information
- [<HKCU>\Control Panel\Desktop] 'SCRNSAVE.EXE' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Control\SecurityProviders] 'SecurityProviders' = 'msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, credssp.dll'
- [<HKLM>\SYSTEM\ControlSet001\Control\Lsa] 'Security Packages' = 'kerberos\nmsv1_0\nschannel\nwdigest\ntspkg'
- '%HOMEPATH%\RDP6\TsCredentials.exe' ##.##.###.## "#####\#######" ######@###
- '%HOMEPATH%\RDP6\TsCredentials.exe' ##.##.###.## /######
- '%HOMEPATH%\RDP6\ConnectionClient.exe' -server 54.94.169.90 -port -user palacio -psw Franca@123 -domain souis -color 24 -alttab 0 -printer on -com off -smartcard off -preview on -remoteapp on -seamless off -disk on -loadbalancing ...
- %HOMEPATH%\RDP6\bkgscpink.bmp
- %TEMP%\autA.tmp
- %HOMEPATH%\RDP6\TsCredentials.exe
- %TEMP%\aut8.tmp
- %HOMEPATH%\RDP6\bkgscgreen.bmp
- %TEMP%\aut9.tmp
- %HOMEPATH%\RDP6\MyPDFprinting\clientenvironment.ini
- <LS_APPDATA>\Microsoft\Credentials\S-1-5-21-2052111302-484763869-725345543-1003\Credentials
- %TEMP%\~DF157.tmp
- %HOMEPATH%\RDP6\MyPDFprinting\alreadyprinted.ini
- C:\webtmp\webprint.txt
- C:\webtmp\alreadyopen.ini
- %APPDATA%\Microsoft\Protect\CREDHIST
- %HOMEPATH%\RDP6\bkgscblue.bmp
- %HOMEPATH%\RDP6\<File name>.txt
- %TEMP%\aut3.tmp
- %HOMEPATH%\RDP6\ConnectionClient.exe
- %TEMP%\aut1.tmp
- %HOMEPATH%\RDP6\mstsc.exe
- %TEMP%\aut2.tmp
- %TEMP%\aut4.tmp
- %TEMP%\aut6.tmp
- %HOMEPATH%\RDP6\bkgsc.bmp
- %TEMP%\aut7.tmp
- %HOMEPATH%\RDP6\languk.ini
- %TEMP%\aut5.tmp
- %HOMEPATH%\RDP6\ico2.ico
- %TEMP%\aut8.tmp
- %TEMP%\aut7.tmp
- %TEMP%\aut9.tmp
- %HOMEPATH%\RDP6\bkgsc.bmp
- %TEMP%\autA.tmp
- %TEMP%\aut6.tmp
- %TEMP%\aut2.tmp
- %TEMP%\aut1.tmp
- %TEMP%\aut3.tmp
- %TEMP%\aut5.tmp
- %TEMP%\aut4.tmp
- '54.##.169.90':3389
- ClassName: 'Shell_TrayWnd' WindowName: ''