Technical Information
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\] 'Images' = '%ALLUSERSPROFILE%\images.exe'
- klrjgqiwk.exe
- %TEMP%\nsw92cd.tmp
- %TEMP%\okzwdhizwk.wto
- %TEMP%\ktoutl.b
- %TEMP%\klrjgqiwk.exe
- %ALLUSERSPROFILE%\images.exe
- '%TEMP%\klrjgqiwk.exe' %TEMP%\ktoutl.b
- '%TEMP%\klrjgqiwk.exe'
- '%ALLUSERSPROFILE%\images.exe'