Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'MPC-HC' = '%APPDATA%\D620C4\D620C4.exe'
- %WINDIR%\syswow64\svchost.exe
- %APPDATA%\d620c4\d620c4.exe
- %APPDATA%\d620c4\d620c4.exe
- DNS ASK xl###rx.info
- '%WINDIR%\syswow64\svchost.exe'