Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Pabo' = '%APPDATA%\Tyap\fogudui.exe'
- '%PROGRAMDATA%\zujduly.exe'
- %WINDIR%\syswow64\msiexec.exe
- %PROGRAMDATA%\zujduly.exe
- %APPDATA%\tyap\fogudui.exe
- http://pl###texw.com/vn2.exe
- DNS ASK pl###texw.com
- '%PROGRAMDATA%\zujduly.exe' ' (with hidden window)
- '%WINDIR%\syswow64\msiexec.exe'