Technical Information
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'Alcmeter' = '%TEMP%\Pkp60sCP9o99th0.exe'
- [<HKLM>\Software\Classes\RKEWAMCFDSOSQEK\shell\open\command] '' = '%TEMP%\Pkp60sCP9o99th0.exe'
- <Drive name for removable media>:\how to decrypt files.txt
- <Drive name for removable media>:\archer.avi
- <Drive name for removable media>:\delete.avi
- %TEMP%\pkp60scp9o99th0.exe