Technical Information
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = '"<SYSTEM32>\ngmuprlhlrtjnh.exe" /shell'
- %WINDIR%\Explorer.EXE
- firefox.exe
- opera.exe
- iexplore.exe
- chrome.exe
- safari.exe
- <SYSTEM32>\ngmuprlhlrtjnh.exe
- 'dr####reproj.com':80
- DNS ASK dr####reproj.com