Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'dgtejucvbsm' = '%HOMEPATH%\dgtejucvbsm\dgtejucvbsm.vbs -VC'
- dgtejucvbsm.exe
- [<HKCU>\Software\LinasFTP\Site Manager]
- [<HKCU>\Software\FlashPeak\BlazeFtp\Settings]
- [<HKCU>\Software\Ghisler\Total Commander]
- [<HKCU>\Software\mIRC]
- [<HKCU>\Software\Far\Plugins\FTP\Hosts]
- [<HKCU>\Software\Far2\Plugins\FTP\Hosts]
- [<HKCU>\Software\VanDyke\SecureFX]
- [<HKLM>\Software\NCH Software\Fling\Accounts]
- [<HKCU>\Software\NCH Software\Fling\Accounts]
- [<HKLM>\Software\NCH Software\ClassicFTP\FTPAccounts]
- [<HKCU>\Software\NCH Software\ClassicFTP\FTPAccounts]
- [<HKCU>\Software\SimonTatham\PuTTY\Sessions]
- [<HKLM>\Software\SimonTatham\PuTTY\Sessions]
- [<HKCU>\Software\Martin Prikryl]
- [<HKLM>\Software\Martin Prikryl]
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook]
- <LS_APPDATA>\nichrome\user data\default\web data
- <LS_APPDATA>\chromium\user data\default\web data
- %APPDATA%\opera software\opera stable\login data
- %APPDATA%\thunderbird\profiles.ini
- %HOMEPATH%\dgtejucvbsm\dgtejucvbsm.exe
- %HOMEPATH%\dgtejucvbsm\dgtejucvbsm.vbs
- %APPDATA%\cea850\01dba1.lck
- %APPDATA%\cea850\01dba1.exe
- %APPDATA%\cea850\01dba1.lck
- from %HOMEPATH%\dgtejucvbsm\dgtejucvbsm.exe to %APPDATA%\cea850\01dba1.exe
- %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-1229272821-842925246-1060284298-1003\f58155b4b1d5a524ca0261c3ee99fb50_5f9fe710-99e6-4c04-be62-a7f1b8b321d1
- DNS ASK ge##y.ru
- '<SYSTEM32>\wscript.exe' "%HOMEPATH%\dgtejucvbsm\dgtejucvbsm.vbs"
- '%HOMEPATH%\dgtejucvbsm\dgtejucvbsm.exe'
- '<SYSTEM32>\wscript.exe' "%HOMEPATH%\dgtejucvbsm\dgtejucvbsm.vbs"' (with hidden window)
- '%HOMEPATH%\dgtejucvbsm\dgtejucvbsm.exe' ' (with hidden window)