Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Updater' = '%APPDATA%\gg.exe'
- %WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe
- %APPDATA%\gg.exe
- %APPDATA%\mcqizadqo.exe
- DNS ASK se#####020.no-ip.org
- '%APPDATA%\mcqizadqo.exe'
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe'