Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\pjzwmccv] 'ImagePath' = '%WINDIR%\SysWOW64\pjzwmccv.sys'
- 'pjzwmccv' %WINDIR%\SysWOW64\pjzwmccv.sys
- qmproxyvpnhelper.exe
- C:\2.txt
- %WINDIR%\vcscontrol.dll
- C:\qmproxyvpnhelper.exe
- %HOMEPATH%\desktop\1.jpg
- %WINDIR%\gg.wav
- %WINDIR%\kq.wav
- %WINDIR%\gb.wav
- %WINDIR%\zero.wav
- %WINDIR%\one.wav
- %WINDIR%\two.wav
- %WINDIR%\three.wav
- %WINDIR%\four.wav
- %WINDIR%\five.wav
- %WINDIR%\six.wav
- %WINDIR%\kq1.wav
- %WINDIR%\syswow64\pjzwmccv.sys
- C:\2.txt
- %WINDIR%\syswow64\pjzwmccv.sys
- %WINDIR%\vcscontrol.dll в %TEMP%\1004927\....\temporaryfile
- ClassName: 'UnrealWindow' WindowName: ''
- 'C:\qmproxyvpnhelper.exe'
- 'C:\qmproxyvpnhelper.exe' ' (со скрытым окном)