Technical Information
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] 'igussvpkx' = '{84eec15e-0c66-51bb-1d77-0c6649d6977d}'
- %WINDIR%\syswow64\uwgxjpny.dat
- %WINDIR%\syswow64\vthfficxk.dll
- %WINDIR%\syswow64\hftrruojw.dll
- %WINDIR%\syswow64\dbpnnqkfs.dll