Technical Information
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'Windows Media Center' = '%WINDIR%\smss.exe'
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %TEMP%\hrgzelvs.t0h.exe
- %TEMP%\njgt3x3b.b3w.exe
- %WINDIR%\smss.exe
- %APPDATA%\chrtmp
- '%TEMP%\hrgzelvs.t0h.exe'
- '%TEMP%\njgt3x3b.b3w.exe'