Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'WerFaultSecurers' = '%WINDIR%\WerFaultSecurers.exe'
- %ALLUSERSPROFILE%\DRM\xs\nqjyxudknzugmahddt
- from <Full path to virus> to %WINDIR%\WerFaultSecurers.exe
- 'ji###.#imindaddy.com':53
- 'ji###.#imindaddy.com':80
- ji###.#imindaddy.com/57F3A8C2D4C68633349CFF5D
- ji###.#imindaddy.com/8DAEABF24AC6EA084C19BAC6
- ji###.#imindaddy.com/8C08D9AC32BE10815A355DB9
- DNS ASK ji###.#imindaddy.com