Technical Information
- %APPDATA%\Microsoft\windows\Start Menu\programs\startup\j49frqbn.lnk
- %ProgramFiles%\nbqrf94j.plz
- %ProgramFiles%\j49frqbn.pff
- '37.##9.53.169':443
- '64.##1.122.10':443
- '%WINDIR%\syswow64\rundll32.exe' C:\PROGRA~3\nbqrf94j.plz,GL300
- '%WINDIR%\syswow64\regedit.exe' -s C:\PROGRA~3\j49frqbn.reg