Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'Appress6' = '%TEMP%\FORCERI\Ginnedto.vbs'
- ginnedto.exe
- %TEMP%\forceri\ginnedto.exe
- %TEMP%\forceri\ginnedto.vbs
- http://pr####gedrvoip.com/mm/bin_TqPrCrT254.bin
- DNS ASK pr####gedrvoip.com
- '%TEMP%\forceri\ginnedto.exe'