Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'kdngL' = 'C:\wybecsnnob\kdngLS\kdngLSWgp.vbs'
- %WINDIR%\microsoft.net\framework\v4.0.30319\installutil.exe
- C:\wybecsnnob\kdngls\kdnglswgp.vbs
- C:\wybecsnnob\kdngls\kdngl.exe
- DNS ASK tt##v.fun
- '%WINDIR%\microsoft.net\framework\v4.0.30319\installutil.exe'