Техническая информация
- [HKLM\System\CurrentControlSet\Services\windows_udp_dll] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\windows_udp_dll] 'ImagePath' = '%ALLUSERSPROFILE%\bc64b5466f\ed43063427.exe'
- 'windows_udp_dll' %ALLUSERSPROFILE%\bc64b5466f\ed43063427.exe
- %ALLUSERSPROFILE%\bc64b5466f\ed43063427.exe
- %WINDIR%\temp\imadc0c.tmp
- %WINDIR%\temp\imadc0c.tmp
- DNS ASK bi###iri.org
- '255.255.255.255':33445
- '%ALLUSERSPROFILE%\bc64b5466f\ed43063427.exe'