Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\lirsgt] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\lirsgt] 'ImagePath' = 'system32\DRIVERS\lirsgt.sys'
- [<HKLM>\System\CurrentControlSet\Services\atksgt] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\atksgt] 'ImagePath' = 'system32\DRIVERS\atksgt.sys'
- 'lirsgt' system32\DRIVERS\lirsgt.sys
- 'atksgt' system32\DRIVERS\atksgt.sys
- %TEMP%\tagessetup_x64.exe
- <DRIVERS>\lirsgt.sys
- <DRIVERS>\atksgt.sys
- %WINDIR%\temp\udd1b9b.tmp
- %WINDIR%\temp\udd1bbb.tmp
- %TEMP%\tagessetup_x64.exe
- %WINDIR%\temp\udd1b9b.tmp
- %WINDIR%\temp\udd1bbb.tmp
- '%TEMP%\tagessetup_x64.exe' 1
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\hotplug.dll,HotPlugDriverBlocked \\.\pipe\PNP_HotPlug_Pipe_1.{29db4be8-09c7-4a36-8559-9b274ac76958}