Техническая информация
- [HKLM\System\CurrentControlSet\Services\ogjpxha] 'Start' = '00000000'
- [HKLM\System\CurrentControlSet\Services\ogjpxha] 'ImagePath' = 'system32\drivers\wqbnn.sys'
- 'ogjpxha' <DRIVERS>\wqbnn.sys
- %WINDIR%\syswow64\jmxf.dll
- %WINDIR%\syswow64\drivers\wqbnn.sys
- '%WINDIR%\syswow64\rundll32.exe' <SYSTEM32>\JmXF.dll,DllRegisterServer' (со скрытым окном)
- '%WINDIR%\syswow64\rundll32.exe' <SYSTEM32>\JmXF.dll,DllUnregisterServer' (со скрытым окном)
- '%WINDIR%\syswow64\rundll32.exe' <SYSTEM32>\JmXF.dll,DllRegisterServer
- '%WINDIR%\syswow64\rundll32.exe' <SYSTEM32>\JmXF.dll,DllUnregisterServer