Technical Information
- %APPDATA%\Microsoft\windows\Start Menu\programs\startup\zjwliih4.lnk
- %ProgramFiles%\4hiilwjz.gsa
- %ProgramFiles%\zjwliih4.bbr
- '19#.#89.105.125':443
- '5.##.81.116':443
- '5.##.81.116':80
- '%WINDIR%\syswow64\rundll32.exe' C:\PROGRA~3\4hiilwjz.gsa,MMS1