Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\Nationalvkf] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Nationalvkf] 'ImagePath' = '<SYSTEM32>\nehvay.exe'
- 'Nationalvkf' <SYSTEM32>\nehvay.exe
- %WINDIR%\windows.exe
- %WINDIR%\syswow64\nehvay.exe
- 'vi###.f3322.net':2018
- DNS ASK vi###.f3322.net
- ClassName: '' WindowName: 'QQ'
- '%WINDIR%\windows.exe'
- '%WINDIR%\syswow64\nehvay.exe'