Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '{4198D660-006E-13DD-F44C-07A76425F732}' = '"%APPDATA%\Ypdeik\ocak.exe"'
- %APPDATA%\Ypdeik\ocak.exe
- <Auxiliary element>
- %TEMP%\tmpc313f05c.bat
- %APPDATA%\Ypdeik\ocak.exe
- 'za####.goodluckwith.us':80
- za####.goodluckwith.us/cn.dat
- DNS ASK za####.goodluckwith.us
- ClassName: 'Indicator' WindowName: ''