Техническая информация
- [HKLM\System\CurrentControlSet\Services\yrpqd] 'Start' = '00000000'
- [HKLM\System\CurrentControlSet\Services\yrpqd] 'ImagePath' = 'system32\drivers\yrpqd.sys'
- 'yrpqd' <DRIVERS>\yrpqd.sys
- %WINDIR%\syswow64\hcmq94.dll
- %WINDIR%\syswow64\drivers\yrpqd.sys
- %WINDIR%\syswow64\le3dv5.bat
- nul
- '%WINDIR%\syswow64\cmd.exe' /c <SYSTEM32>\lE3Dv5.bat' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c <SYSTEM32>\lE3Dv5.bat
- '%WINDIR%\syswow64\ping.exe' -n 3 127.0.0.1