Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\userinit.exe] 'Debugger' = 'execbmem.exe'
- %WINDIR%\Explorer.EXE
- opera.exe
- <SYSTEM32>\execbmem.exe
- '74.##5.232.51':80
- 74.##5.232.51/
- DNS ASK ra###rquest.com
- DNS ASK bi#####ked.sendsmtp.com
- DNS ASK fu##y.net
- DNS ASK www.google.com
- DNS ASK re##ck.com