Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'BmsWJ7fEjeIr0v28234A' = '<SYSTEM32>\UYXwkUVrlBx0GaH.exe'
- <SYSTEM32>\UYXwkUVrlBx0GaH.exe 5985<Full path to virus>
- %APPDATA%\przcA1uvDoFp5W7Security Guard 2012.ico
- <SYSTEM32>\UYXwkUVrlBx0GaH.exe
- %APPDATA%\ldr.ini
- '74.##5.232.51':80
- DNS ASK google.com
- '<Private IP address>':1033