Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'b48762f63e2d28a0f115e199ad28dad8' = '"%APPDATA%\savhost.exe" ..'
- [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] 'b48762f63e2d28a0f115e199ad28dad8' = '"%APPDATA%\savhost.exe" ..'
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%APPDATA%\savhost.exe" "savhost.exe" ENABLE
- %APPDATA%\savhost.exe
- DNS ASK qu####33.no-ip.org
- '%APPDATA%\savhost.exe'
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%APPDATA%\savhost.exe" "savhost.exe" ENABLE' (with hidden window)