Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\gbwxxquzyx.url
- %WINDIR%\notepad.exe
- %PROGRAMDATA%\zrbebqtcgq\cfgi
- %PROGRAMDATA%\zrbebqtcgq\cfg
- %PROGRAMDATA%\zrbebqtcgq\sysdrv32
- %PROGRAMDATA%\zrbebqtcgq\r.vbs
- %PROGRAMDATA%\zrbebqtcgq\r.vbs
- from %PROGRAMDATA%\zrbebqtcgq\sysdrv32 to %PROGRAMDATA%\zrbebqtcgq\sysdrv32.exe
- %PROGRAMDATA%\zrbebqtcgq\r.vbs
- '92.##.197.190':5657
- '%WINDIR%\notepad.exe' -c "%PROGRAMDATA%\ZRBEbQTcgq\cfg"
- '%WINDIR%\syswow64\cmd.exe' /C WScript "%PROGRAMDATA%\ZRBEbQTcgq\r.vbs"
- '%WINDIR%\syswow64\wscript.exe' "%PROGRAMDATA%\ZRBEbQTcgq\r.vbs"
- '%WINDIR%\notepad.exe' -c "%PROGRAMDATA%\ZRBEbQTcgq\cfgi"