Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Control\Print\Providers\7uOC79u17iQ179o1o] 'Name' = '"%TEMP%\9aA1.tmp"'
- [<HKLM>\SYSTEM\ControlSet001\Services\3179cEI9] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\a3kU93i79] 'Start' = '00000002'
- <SYSTEM32>\spoolsv.exe
- <DRIVERS>\179e1a9k17g.sys
- <DRIVERS>\K1yWS1eI3q793o7oCE.sys
- %TEMP%\9aA1.tmp
- %TEMP%\9aA1.tmp
- <DRIVERS>\K1yWS1eI3q793o7oCE.sys