Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\hjgruilhbmudpm] 'start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\pcbdwqpuxterxegn] 'start' = '00000001'
- <SYSTEM32>\spoolsv.exe
- <DRIVERS>\pcbdwqpuxterxegn.sys
- <DRIVERS>\hjgruiuynsbpfj.sys
- %TEMP%\seeqsxcxtk.tmp
- %TEMP%\pyrbcxrpph.tmp