Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'WinDLL (service.exe)' = 'service.exe'
- %WINDIR%\service.exe
- %WINDIR%\service.exe
- '77.##0.185.67':80
- DNS ASK gs####83.google.com
- DNS ASK de
- DNS ASK in#.####.messagingengine.com
- DNS ASK or#
- DNS ASK co#
- DNS ASK mx#.mail.ru
- DNS ASK gm######tp-in.l.google.com