Technical Information
- %HOMEPATH%\Start Menu\Programs\Startup\WNBXxRlepu9U5fq.lnk
- %ProgramFiles%\GKrC6bdVcpA4hsd.exe
- 'mo###echdi.com':80
- 'li###itopr.com':80
- 'localhost':1036
- http://mo###echdi.com/find.php?g=#######################################
- http://li###itopr.com/main.php?g=#######################################
- DNS ASK mo###echdi.com
- DNS ASK li###itopr.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''