Technical Information
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = '"%APPDATA%\system32dll.exe\q5AVKKHZo1nk.exe",explorer.exe'
- %HOMEPATH%\Start Menu\Programs\Startup\system32dll.exe
- %APPDATA%\system32dll.exe\q5AVKKHZo1nk.exe
- %APPDATA%\system32dll.exe\q5AVKKHZo1nk.exe
- 'du####.myddns.me':1604
- 'localhost':333
- DNS ASK du####.myddns.me
- '<Full path to file>'