Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'winhelp.exe' = '%APPDATA%\YlFlXlFbQ0k=\winhelp.exe'
- '%APPDATA%\YlFlXlFbQ0k=\winhelp.exe' <Full path to file>
- '%APPDATA%\YlFlXlFbQ0k=\winhelp.exe'
- winhelp.exe
- %APPDATA%\YlFlXlFbQ0k=\winhelp.exe
- %APPDATA%\YlFlXlFbQ0k=\winhelp.exe
- 'nu##mps.xyz':80
- http://nu##mps.xyz/pixies/system/temp/etc/tasks.php
- DNS ASK nu##mps.xyz