Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\pgu8q6] 'Start' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\pgu8q6] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\9efiy7snb] 'Start' = '00000002'
- '<SYSTEM32>\is6y.exe'
- <DRIVERS>\pgu8q6.sys
- <SYSTEM32>\l23go.dll
- <DRIVERS>\9efiy7snb.sys
- <SYSTEM32>\is6y.exe
- %HOMEPATH%\Favorites\КХІШ.url
- 'tm#.#arfly.org':80
- tm#.#arfly.org/rpt103p60000
- tm#.#arfly.org/rpt5p60000
- DNS ASK tm#.#arfly.org