Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '%TEMP%\Bdez.exe' = '%TEMP%\Bdez.exe'
- %APPDATA%\microsoft\windows\start menu\programs\startup\gtfo.exe
- %TEMP%\hmaudob.exe
- %TEMP%\oqwxheabu.exe
- %TEMP%\bdez.exe
- %TEMP%\shgfm.exe
- %TEMP%\screen.jpg
- http://ic###azip.com/
- http://ip#####.#hatismyipaddress.com/
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- DNS ASK ic###azip.com
- DNS ASK ip#####.#hatismyipaddress.com
- DNS ASK di###rdapp.com
- DNS ASK ge###tatool.com
- DNS ASK microsoft.com
- '%TEMP%\hmaudob.exe'
- '%TEMP%\oqwxheabu.exe'
- '%TEMP%\bdez.exe'
- '%TEMP%\shgfm.exe'