Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'SystemUpdate_mqecKg' = '"%APPDATA%\temp_gHBgPrYnutIc.exe"'
- %APPDATA%\packer_debug.txt
- %APPDATA%\temp_ghbgprynutic.exe
- %APPDATA%\debug_xvzdcjtebrsa.exe
- %TEMP%\onefile_2548_133903012558770000\obf_a8ab4437213649a0a3740efb5036c733.exe
- %TEMP%\onefile_2548_133903012558770000\python39.dll
- %TEMP%\onefile_2548_133903012558770000\select.pyd
- %TEMP%\onefile_2548_133903012558770000\unicodedata.pyd
- %TEMP%\onefile_2548_133903012558770000\vcruntime140.dll
- %TEMP%\onefile_2548_133903012558770000\obf_a8ab4437213649a0a3740efb5036c733.exe
- %TEMP%\onefile_2548_133903012558770000\python39.dll
- %TEMP%\onefile_2548_133903012558770000\select.pyd
- %TEMP%\onefile_2548_133903012558770000\unicodedata.pyd
- %TEMP%\onefile_2548_133903012558770000\vcruntime140.dll
- '%APPDATA%\temp_ghbgprynutic.exe'
- '%TEMP%\onefile_2548_133903012558770000\obf_a8ab4437213649a0a3740efb5036c733.exe'
- '%APPDATA%\temp_ghbgprynutic.exe' ' (with hidden window)