Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\np.lnk
- %APPDATA%\microsoft\windows\start menu\programs\startup\sys.lnk
- %LOCALAPPDATA%\winint.exe
- %HOMEPATH%\documents\np.lnk
- %LOCALAPPDATA%\libio.dll
- %LOCALAPPDATA%\sys.exe
- %HOMEPATH%\documents\sys.lnk
- 'll####23.hopto.org':332
- http://pa###bin.com/raw.php?i=########
- DNS ASK pa###bin.com
- DNS ASK ll####23.hopto.org
- '%LOCALAPPDATA%\winint.exe'
- '%LOCALAPPDATA%\sys.exe'