Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'Ieuu' = '"%WINDIR%\MANTEC~1\svchost.exe" -vt yax'
- %WINDIR%\mantec~1\svchost.exe
- %WINDIR%\mantec~1\svchost.exe
- '63.##1.135.16':80
- DNS ASK nf.###erinfo.com
- DNS ASK cu.###erinfo.com
- '%WINDIR%\mantec~1\svchost.exe' -vt yax