Техническая информация
- [HKLM\System\CurrentControlSet\Services\GWSFCtrlCDO010] 'Start' = '00000001'
- [HKLM\System\CurrentControlSet\Services\GWSFCtrlCDO010] 'ImagePath' = 'System32\svjtime.sys'
- 'GWSFCtrlCDO010' System32\svjtime.sys
- %TEMP%\rarsfx0\upd.exe
- %TEMP%\update.ini
- %WINDIR%\syswow64\self.exe
- %WINDIR%\syswow64\svjtime.sys
- %WINDIR%\syswow64\billdll.dll
- %WINDIR%\syswow64\rwylib.dll
- %WINDIR%\syswow64\rwysup.exe
- %WINDIR%\syswow64\sendcmd.exe
- %WINDIR%\syswow64\wwm.dll
- %WINDIR%\syswow64\rwyncmc.exe
- %WINDIR%\syswow64\timer.dll
- %WINDIR%\syswow64\self.exe
- %TEMP%\rarsfx0\upd.exe
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'rzxcmg' WindowName: 'rzxcmg'
- '%TEMP%\rarsfx0\upd.exe'
- '%WINDIR%\syswow64\self.exe' /a
- '%WINDIR%\syswow64\rwyncmc.exe' /u