Техническая информация
- [HKLM\System\CurrentControlSet\Services\mgqrlk] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\mgqrlk] 'ImagePath' = '<SYSTEM32>\svchost.exe -kmgqrlk'
- [HKLM\SYSTEM\CurrentControlSet\Services\mgqrlk\pARAMETERS] 'ServiceDll' = '<SYSTEM32>\kjqkdd.dll'
- [HKLM\SYSTEM\ControlSet003\Services\mgqrlk\pARAMETERS] 'ServiceDll' = '<SYSTEM32>\kjqkdd.dll'
- [HKLM\SYSTEM\ControlSet003\Services\mgqrlk] 'Start' = '00000002'
- 'mgqrlk' <SYSTEM32>\svchost.exe -kmgqrlk
- %WINDIR%\syswow64\0004b12b.sys
- %WINDIR%\syswow64\kjqkdd.dll
- 'ss####88.3322.org':8000
- DNS ASK ss####88.3322.org
- '%WINDIR%\syswow64\svchost.exe' -kmgqrlk