Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\hjgruilmkvpapq] 'start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\bchwbuyxcpgegowf] 'start' = '00000001'
- '<SYSTEM32>\spoolsv.exe'
- <DRIVERS>\bchwbuyxcpgegowf.sys
- <DRIVERS>\hjgruijgtbiynx.sys
- %TEMP%\hpylqbwwbb.tmp
- %TEMP%\oosvnnxrcr.tmp
- '21#.#33.110.21':443