Technical Information
- %HOMEPATH%\start menu\programs\startup\<File name>.lnk
- %WINDIR%\tasks\bidaily synchronize task.job
- %ALLUSERSPROFILE%\application data\{d437107c-658b-c9d5-d437-7107c65841f1}\<File name>.exe
- %ALLUSERSPROFILE%\application data\{d437107c-658b-c9d5-d437-7107c65841f1}\<File name>.dat
- DNS ASK ki####nqview.info
- DNS ASK sh####-models.com