Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{F8477C3B-169E-2F9A-12FC-1004D4476315}] 'stubpath' = '<SYSTEM32>\Bifrost\server.exe s'
- %WINDIR%\explorer.exe
- launcher.exe
- <SYSTEM32>\bifrost\server.exe
- <SYSTEM32>\bifrost\server.exe
- DNS ASK ch####hi.no-ip.info
- '%ProgramFiles%\opera\launcher.exe'