Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'gjo' = '%APPDATA%\gdpacy\jknfry.exe'
- '%APPDATA%\gdpacy\jknfry.exe' -installer "<Full path to file>"
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\F4EA68BBDED392A0EA5CD331[1].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\yahoo[1]
- %APPDATA%\gdpacy\jknfry.exe
- 'te##serl.ru':80
- '67.##5.160.76':80
- http://www.ya##o.com/ via 67.##5.160.76
- DNS ASK te##serl.ru
- DNS ASK www.ya##o.com