Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{5DB04BC9-91DE-B82F-2E5F-DD54FA5D83F4}] 'stubpath' = '<SYSTEM32>\V3Medic.exe'
- '<SYSTEM32>\reg.exe' delete "HKEY_CURRENT_USER\Software\Microsoft\Active Setup\Installed Components\{5DB04BC9-91DE-B82F-2E5F-DD54FA5D83F4}" /f
- <SYSTEM32>\V3Medic.exe
- 'bl##.daum.net':80
- 'bl##.#ina.com.cn':80
- '17#.#39.190.38':80
- http://bl##.daum.net/xml/rss/opaoxf2
- http://bl##.#ina.com.cn/s/blog_14557d58d0102vbkv.html
- http://17#.#39.190.38/pro1.asp
- DNS ASK bl##.daum.net
- DNS ASK bl##.#ina.com.cn