Infected with NanoCore. Drops C:\Users\admin\AppData\Roaming\90059C37-1320-41A4-B58D-2B75A9850D2F\TCP Monitor\tcpmon.exe. Changes the HKEY_CURRENT_USER autorun registry to run \TCP Monitor\tcpmon.exe. Creates a new task and connects to 151.45.239.97 port 54984.