Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\wudfhost.url
- '%APPDATA%\hc5tbg.exe'
- %WINDIR%\syswow64\svchost.exe
- %APPDATA%\hc5tbg.exe
- %HOMEPATH%\wudfhost\wudfhost.vbs
- %HOMEPATH%\wudfhost\credwiz.exe
- http://se##-bc.com/royal/helper/gd/zt/cola.exe
- DNS ASK se##-bc.com
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\svchost.exe'