Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'iohlkn' = '<Full path to file>'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'riswcv' = '<Full path to file>'
- <Current directory>\set01.ico
- C:\yieizw\kwtoqxwuhi.exe
- <Current directory>\set02.ico
- C:\ttqwmo\yrrsvkkk.exe
- <Current directory>\set01.ico
- <Current directory>\set02.ico
- 'C:\ttqwmo\yrrsvkkk.exe'
- '<SYSTEM32>\regsvr32.exe' /s scrrun.dll' (with hidden window)
- 'C:\ttqwmo\yrrsvkkk.exe' ' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c rd "<Current directory>"' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' /s scrrun.dll
- '<SYSTEM32>\cmd.exe' /c rd "<Current directory>"