Technical Information
- [HKLM\SYSTEM\CurrentControlSet\Services\abc2.0] 'ImagePath' = '%TEMP%\~abc3aTqz.sys'
- [HKLM\SYSTEM\CurrentControlSet\Services\abc2.0] 'ImagePath' = '%TEMP%\~abcE1P5m.sys'
- 'abc2.0' %TEMP%\~abc3aTqz.sys
- 'abc2.0' %TEMP%\~abcE1P5m.sys
- %TEMP%\~abc3aTqz.sys
- %TEMP%\~abcE1P5m.sys
- %TEMP%\d0k37vb41.exe
- %TEMP%\~abc3aTqz.sys
- %TEMP%\~abcE1P5m.sys
- %HOMEPATH%\desktop\google chrome.lnk
- '%TEMP%\d0k37vb41.exe'
- '%WINDIR%\syswow64\cmd.exe' /c start %TEMP%\d0K37vB41.exe
- '%WINDIR%\syswow64\cmd.exe' /c start %TEMP%\d0K37vB41.exe' (with hidden window)