Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'JavaUpdtr' = '%TEMP%\JavaUpdtr.exe'
- svchost.exe
- %TEMP%\app\app.ine
- %TEMP%\javaupdtr.exe
- %TEMP%\app\svchost.exe
- from %TEMP%\app\app.ine to %TEMP%\app\svchost.exe
- DNS ASK kj####ts.zapto.org
- '%TEMP%\app\svchost.exe'