Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\dpsqjuwinvj] 'Start' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\dpsqjuwinvj] 'ImagePath' = 'system32\drivers\jnjyfumgrfnf.sys'
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\DLL2.tmp
- <SYSTEM32>\DLL1.tmp
- <DRIVERS>\jnjyfumgrfnf.sys
- 'bo###flex.in':80
- bo###flex.in/check.php?ve##########################################
- DNS ASK bo###flex.in