Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ibmxvtfiyq' = '<SYSTEM32>\regsvr32.exe /s "<Full path to file>"'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30D5D976-2597-DB24-3024-D3B6EFDD06B2}]
- 'localhost':5152
- DNS ASK ad#.##tupbanner.com
- ClassName: '' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''