Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'KXMYHNDPHSXVZTH' = '%ALLUSERSPROFILE%\SLCOCVWTZOEOEAI\DJPVHTKBUDSMHST.exe'
- %WINDIR%\explorer.exe
- %ALLUSERSPROFILE%\slcocvwtzoeoeai\djpvhtkbudsmhst.exe
- DNS ASK mt.###dierofgod.at