Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'zsdcfwpq' = 'rundll32 "%WINDIR%\lqpaborq.dll",Register'
- %WINDIR%\Explorer.EXE
- %WINDIR%\lqpaborq.dll
- 'yu#####entovezalio.biz':8080
- 'localhost':1037
- DNS ASK yu#####entovezalio.biz
- ClassName: 'Indicator' WindowName: ''