Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'Gxgbq' = '%APPDATA%\Gxgbq.exe'
- %APPDATA%\gxgbq.exe
- %ALLUSERSPROFILE%\mjhfbey\registros.dat
- %ALLUSERSPROFILE%\mjhfbey\registros.dat
- 'ba####24.con-ip.com':2026
- DNS ASK ba####24.con-ip.com
- '<Full path to file>' ' (with hidden window)