Technical Information
- [<HKLM>\System\CurrentControlSet\Services\Wsiczg olyhgdmy] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Wsiczg olyhgdmy] 'ImagePath' = '%ProgramFiles(x86)%\Microsoft Hbdxua\Aodhisu.exe'
- %ProgramFiles%\apppatch\a.dll
- %ProgramFiles(x86)%\microsoft hbdxua\aodhisu.exe
- http://a.###bank.me/a.dll
- DNS ASK a.###bank.me
- '%ProgramFiles(x86)%\microsoft hbdxua\aodhisu.exe'