Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\890207d7-2112-4788-8692-49ab13a2592f.vbs
- %TEMP%\nsu9a9.tmp
- %TEMP%\nsq3cac.tmp\ffq0g7mc.txt
- %TEMP%\nsq3cac.tmp\rn1ot3rx.tq3
- %TEMP%\nsq3cac.tmp\uit3dhqu.agn
- %TEMP%\nsq3cac.tmp\hblpugdwrof.dll
- %PROGRAMDATA%\fontdrvhost.exe.config
- %TEMP%\nsq3cab.tmp
- %TEMP%\nsq3cac.tmp\image-drole-00226.jpg
- %PROGRAMDATA%\fontdrvhost.exe
- %TEMP%\nsz9c9.tmp\image-drole-00226.jpg
- %TEMP%\nsz9c9.tmp\ffq0g7mc.txt
- %TEMP%\nsz9c9.tmp\rn1ot3rx.tq3
- %TEMP%\nsz9c9.tmp\uit3dhqu.agn
- %TEMP%\nsz9c9.tmp\hblpugdwrof.dll
- <Full path to file>.config
- %TEMP%\nsz9c9.tmp\clr.dll
- %TEMP%\nsq3cac.tmp\clr.dll
- <Full path to file>.config
- %PROGRAMDATA%\fontdrvhost.exe.config
- '%PROGRAMDATA%\fontdrvhost.exe'
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\890207d7-2112-4788-8692-49ab13a2592f.vbs"' (with hidden window)
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\890207d7-2112-4788-8692-49ab13a2592f.vbs"