Technical Information
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'lpjqbhsz' = 'C:\oszjqxhovc\xkrbip.exe'
- %WINDIR%\synaptics.7z
- %WINDIR%\synaptics.rs
- C:\oszjqxhovc\xkrbip.exe
- <Current directory>\update.bat
- 'C:\oszjqxhovc\xkrbip.exe'
- '%WINDIR%\syswow64\cmd.exe' /c <Current directory>\update.bat
- '%WINDIR%\syswow64\timeout.exe' /T 2
- '%WINDIR%\syswow64\timeout.exe' /T 3