Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'LocalSessionManager' = '"%APPDATA%\lsm.exe"'
- ClassName: 'OLLYDBG' WindowName: '(null)'
- %APPDATA%\lsm.exe
- 'mp##.hopto.org':1080
- DNS ASK po##.dlunch.net
- DNS ASK mp##.hopto.org
- ClassName: 'Indicator' WindowName: '(null)'