Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'daumAng' = '<Полный путь к вирусу>'
- 'ch###g.xvv.kr':80
- ch###g.xvv.kr/xe/addons/counter/conf/request.php?xg############################################################
- DNS ASK ch###g.xvv.kr
- ClassName: 'Indicator' WindowName: ''