Technical Information
- %WINDIR%\syswow64\svchost.exe
- [HKCU\Software\FTPWare\COREFTP\Sites\]
- [HKCU\Software\Martin Prikryl\WinSCP 2\Sessions\]
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %APPDATA%\opera software\opera stable\login data
- %LOCALAPPDATA%\microsoft\edge\user data\default\login data
- %LOCALAPPDATA%\microsoft\edge\user data\default\web data
- %TEMP%\aut94d9.tmp
- %TEMP%\translucently
- %TEMP%\aut9b14.tmp
- %TEMP%\tilths
- %APPDATA%\microsoft\windows\templates\nkynfzuhnigv-user\logindata
- %APPDATA%\microsoft\windows\templates\nkynfzuhnigv-user\webdata
- '%WINDIR%\syswow64\svchost.exe'