Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\LGJRADMIN] 'Start' = '00000002'
- '<SYSTEM32>\lgjradmin.exe'
- '<SYSTEM32>\lgjradmin.exe' /install /silent
- '<SYSTEM32>\net1.exe' start lgjradmin
- <SYSTEM32>\lgjradmin.exe
- 'www.wx##0.com':80
- www.wx##0.com/radmin/radmin.rar
- DNS ASK www.wx##0.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'