Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\4fbL0vSGpg0] 'ImagePath' = '<DRIVERS>\4fbL0vSGpg0.sys'
- %TEMP%\1.tmp
- %TEMP%\2.tmp
- %TEMP%\3.tmp
- <DRIVERS>\4fbL0vSGpg0.sys
- C:\cscapi.dll
- <SYSTEM32>\SE.key
- %TEMP%\1.tmp
- %TEMP%\2.tmp
- %TEMP%\3.tmp
- <DRIVERS>\4fbL0vSGpg0.sys
- '<SYSTEM32>\notepad.exe'