Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'rbwgpktpyie' = '%APPDATA%\rwsclgpyuea\jsoxhdmi.exe "%TEMP%\ccdyg.exe" %LOCALAPPDATA%\T�'
- ccdyg.exe
- %TEMP%\nstfdc0.tmp
- %TEMP%\novgyb.g
- %TEMP%\nrxgki.ev
- %TEMP%\ccdyg.exe
- %APPDATA%\rwsclgpyuea\jsoxhdmi.exe
- '%TEMP%\ccdyg.exe' %TEMP%\nrxgki.ev
- '%TEMP%\ccdyg.exe'
