Техническая информация
- [HKLM\System\CurrentControlSet\Services\WJLYZCQQ] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\WJLYZCQQ] 'ImagePath' = '%ALLUSERSPROFILE%\xcfjiizjxqcl\tamrgnqsorqe.exe'
- 'WJLYZCQQ' %ALLUSERSPROFILE%\xcfjiizjxqcl\tamrgnqsorqe.exe
- <SYSTEM32>\conhost.exe
- %WINDIR%\explorer.exe
- %ALLUSERSPROFILE%\xcfjiizjxqcl\tamrgnqsorqe.exe
- %WINDIR%\temp\iwmxxariuwbq.sys
- 'mi##.bmpool.org':6004
- 'mi##.bmpool.org':6004
- DNS ASK mi##.bmpool.org
- '%ALLUSERSPROFILE%\xcfjiizjxqcl\tamrgnqsorqe.exe'
- '<SYSTEM32>\sc.exe' delete "WJLYZCQQ"
- '<SYSTEM32>\sc.exe' create "WJLYZCQQ" binpath= "%ALLUSERSPROFILE%\xcfjiizjxqcl\tamrgnqsorqe.exe" start= "auto"
- '<SYSTEM32>\sc.exe' stop eventlog
- '<SYSTEM32>\sc.exe' start "WJLYZCQQ"
- '%WINDIR%\explorer.exe'