Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'bwsaknpomeeuvx' = '"%ALLUSERSPROFILE%\Application Data\qkmzmdawsubvvq\rptmdezhgswvfw.exe"'
- rptmdezhgswvfw.exe
- %ALLUSERSPROFILE%\Application Data\qkmzmdawsubvvq\rptmdezhgswvfw.exe
- '%ALLUSERSPROFILE%\Application Data\qkmzmdawsubvvq\rptmdezhgswvfw.exe'
- '<Full path to file>'