Technical Information
- [<HKLM>\System\CurrentControlSet\Services\Wswmyg oqymgioq] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Wswmyg oqymgioq] 'ImagePath' = '%ProgramFiles(x86)%\Microsoft Gborux\Fhprlnb.exe'
- 'Wswmyg oqymgioq' %ProgramFiles(x86)%\Microsoft Gborux\Fhprlnb.exe
- %ProgramFiles(x86)%\microsoft gborux\fhprlnb.exe
- C:\3076.vbs
- C:\3076.vbs
- '11#.#31.201.81':1988
- '%ProgramFiles(x86)%\microsoft gborux\fhprlnb.exe'
- '%ProgramFiles(x86)%\microsoft gborux\fhprlnb.exe' Win7
- '%WINDIR%\syswow64\wscript.exe' "C:\3076.vbs"
- '%WINDIR%\syswow64\wscript.exe' "C:\3076.vbs"' (with hidden window)