Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'svchost' = '<Full path to file>'
- %HOMEPATH%\start menu\programs\startup\svchost.exe
- %HOMEPATH%\start menu\programs\startup\explorer.js
- %HOMEPATH%\start menu\programs\startup\google.url
- DNS ASK li######st-37479.portmap.io