Technical Information
- <SYSTEM32>\comres.dll with <SYSTEM32>\comres.dll
- <SYSTEM32>\comres.dll
- '<SYSTEM32>\GTH02576.exe' %WINDIR%\fOnTS\comresx.ttf dns <Full path to virus>
- Handler for all processes: %WINDIR%\fOnTS\comresx.ttf
- %WINDIR%\Fonts\GTH02576.fOn
- <SYSTEM32>\GTH02576.exe
- %WINDIR%\Fonts\GTH02576.tTf
- <SYSTEM32>\muksfv1.dll
- %WINDIR%\Fonts\comresx.ttf
- from <SYSTEM32>\comres.dll to <SYSTEM32>\sysGTH.dll