Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'xsnmvqpwtgdmxajsp' = '<SYSTEM32>\srv95.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\mxqrupwoxlSv] 'Start' = '00000002'
- <SYSTEM32>\svchost.exe -k DcomSec
- %TEMP%\lse2.tmp
- <SYSTEM32>\svcmxqrupw.dll
- <SYSTEM32>\srv95.exe
- C:\logbot.txt
- %TEMP%\lis1.tmp