Техническая информация
- [HKLM\System\CurrentControlSet\Services\Rrykpm Baackxoh Mqs] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Rrykpm Baackxoh Mqs] 'ImagePath' = '<SYSTEM32>\svchost.exe -k imgsvc'
- 'Rrykpm Baackxoh Mqs' <SYSTEM32>\svchost.exe -k imgsvc
- ClassName: 'Regmonclass', WindowName: ''
- ClassName: 'Filemonclass', WindowName: ''
- %TEMP%\sea86e.tmp
- C:\1012900.dll
- C:\nt_path.bmp
- C:\net-temp.ini
- %ProgramFiles(x86)%\gtwy\bjsgyugbv.pic
- %ProgramFiles(x86)%\gtwy\bjsgyugbv.pic
- %TEMP%\sea86e.tmp
- C:\net-temp.ini
- C:\net-temp.ini
- DNS ASK xu####lei.3322.org
- ClassName: '4823-00000029' WindowName: ''
- ClassName: '18467-41' WindowName: ''