Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'BBB9' = '"%TEMP%\BBB10.exe"'
- [<HKLM>\SYSTEM\ControlSet001\Services\zfdzecm] 'Start' = '00000000'
- C:\wxdhtq.txt
- <DRIVERS>\wmiq.sys
- %TEMP%\BBB10.exe
- 'in###.#wardspace.co.uk':80
- in###.#wardspace.co.uk/count.php
- DNS ASK in###.#wardspace.co.uk