Technical Information
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'Final' = '"<Full path to file>"'
- %WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe
- '255.255.255.255':4943
- DNS ASK dm#####er4u.zapto.org
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe'