Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Insomnia Live' = '%HOMEPATH%\AppData\live.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Insomnia Live' = '%PROGRAMDATA%\bigrsrwp.exe'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'QzcxOTlGRkZFNjg4RjVGQ0' = '%PROGRAMDATA%\bigrsrwp.exe'
- %HOMEPATH%\appdata\live.exe
- %PROGRAMDATA%\bigrsrwp.exe
- %HOMEPATH%\qzcxotl.exe
- %PROGRAMDATA%\bigrsrwp.exe
- %HOMEPATH%\qzcxotl.exe
- http://ap#.##pmania.com/
- DNS ASK ap#.##pmania.com
- DNS ASK ir#.#ypur.com
- '%HOMEPATH%\appdata\live.exe'
- '%PROGRAMDATA%\bigrsrwp.exe'
- '%HOMEPATH%\qzcxotl.exe' %PROGRAMDATA%\bigrsrwp.exe 1220