Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'yPz26Vx' = '%HOMEPATH%\oQb70Hc\system.exe'
- Windows Task Manager (Taskmgr)
- %TEMP%\dYe66Jy.EV1
- %TEMP%\aut1.tmp
- %TEMP%\dYe66Jy.EV1
- %TEMP%\aut1.tmp
- 'al######187.3utilities.com':1604
- DNS ASK al######187.3utilities.com