Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'md71g' = '%APPDATA%\gdcgvf1go.exe'
- gdcgvf1go.exe
- %APPDATA%\gdcgvf1go.exe
- 'mk###i4kdsz.com':80
- 'ow###rasuek.com':80
- http://mk###i4kdsz.com/890/87.html
- http://ow###rasuek.com/635/499.html
- DNS ASK ko##od.net
- DNS ASK mk###i4kdsz.com
- DNS ASK ow###rasuek.com
- '%APPDATA%\gdcgvf1go.exe'