Техническая информация
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\] 'optimize' = '%WINDIR%\Web\EndOptimize.exe'
- [HKLM\SYSTEM\CurrentControlSet\Services\exyojc\] 'ImagePath' = '<PATH_SAMPLE>.sys'
- [HKLM\SYSTEM\CurrentControlSet\Services\exyojc\] 'Start' = '00000001'
- 'exyojc' <PATH_SAMPLE>.sys