Technical Information
- '<SYSTEM32>\rundll32.exe' %PROGRAMDATA%\YVPheBX.dll,DllRegisterServer
- http://wm######xxbcxmucxmlc.com/files/april15.dll
- DNS ASK wm######xxbcxmucxmlc.com
- '<SYSTEM32>\rundll32.exe' %PROGRAMDATA%\YVPheBX.dll,DllRegisterServer' (with hidden window)