Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'java1' = '<Full path to virus>'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{3ED99CD9-25F0-95CC-3D65-63EB04D21964}] 'StubPath' = '<Full path to virus>'
- 'rn####.no-ip.info':3460
- DNS ASK rn####.no-ip.info
- '<Private IP address>':1036