Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'KavSvc' = '<SYSTEM32>\kkljua.exe reg_run'
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\dduk.exe
- <SYSTEM32>\ccxnqab.exe
- <SYSTEM32>\rrgwv.dll
- %WINDIR%\aarov.dll
- <SYSTEM32>\qqgay.dat
- <SYSTEM32>\eeypckr.dll
- <SYSTEM32>\kkljua.exe
- '<SYSTEM32>\kkljua.exe'