Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'CRNJEUFU2REG.KAYC' = '%APPDATA%\fVKiiXMS.exe'
- '%APPDATA%\fVKiiXMS.exe'
- chrome.exe
- %APPDATA%\UPDATADECHROME\manifest.json
- %APPDATA%\UPDATADECHROME\img\logo.png
- %APPDATA%\UPDATADECHROME\js\consignado.js
- %APPDATA%\UPDATADECHROME\js\orientado.js
- %APPDATA%\UPDATADECHROME\js\global.js
- %APPDATA%\UPDATADECHROME\img\128.png
- %APPDATA%\DLL.ZIP
- %APPDATA%\ARQUIVO2.ZIP
- %APPDATA%\fVKiiXMS.exe
- %APPDATA%\UPDATADECHROME\img\48.png
- %APPDATA%\JCS.Components.NeroBar.dll
- 'i.##gur.com':80
- 'pa###bin.com':80
- 'wp#d':80
- 'www.go###e.com.br':443
- http://pa###bin.com/raw/ECuPECEq
- http://pa###bin.com/raw/PXTMLmu3
- http://pa###bin.com/raw/gv4479Gb
- http://pa###bin.com/raw/m3DruQMp
- http://i.##gur.com/giWZwMh.png
- http://11#.#11.111.1/wpad.dat via wp#d
- http://i.##gur.com/gUewDMb.png
- http://i.##gur.com/6Q72jqn.png
- DNS ASK i.##gur.com
- DNS ASK pa###bin.com
- DNS ASK wp#d
- DNS ASK www.go###e.com.br
- ClassName: 'Indicator' WindowName: ''