Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'pyienwscxh' = '%APPDATA%\pueajsoxhdm\irbwgpl.exe "%TEMP%\clfdtave.exe" %LOCALAPPDATA%�'
- clfdtave.exe
- %TEMP%\nsre8e8.tmp
- %TEMP%\ayfkgbtlt.b
- %TEMP%\hnuvnlvlzaq.yfm
- %TEMP%\clfdtave.exe
- %APPDATA%\pueajsoxhdm\irbwgpl.exe
- '%TEMP%\clfdtave.exe' %TEMP%\hnuvnlvlzaq.yfm
- '%TEMP%\clfdtave.exe'