Troj/Dloader-BW attempts to download and execute EXE files from remote websites to the Windows system folder as intron.exe, ir.exe, lpt.exe and usb.exe.
The Trojan copies itself to the Windows system folder as twink64.exe and creates the following registry entry to run itself on system logon:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
ControlPanel = <Windows system>\twink64.exe internat.dll,LoadKeyboardProfile