Техническая информация
- [HKLM\System\CurrentControlSet\Services\Rssccy isgwqgqm] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Rssccy isgwqgqm] 'ImagePath' = '%ProgramFiles(x86)%\Microsoft Gwcyui\Mvrdjvs.exe'
- 'Rssccy isgwqgqm' %ProgramFiles(x86)%\Microsoft Gwcyui\Mvrdjvs.exe
- ClassName: 'Regmonclass', WindowName: ''
- ClassName: 'Filemonclass', WindowName: ''
- %ProgramFiles(x86)%\microsoft gwcyui\mvrdjvs.exe
- %ProgramFiles(x86)%\microsoft gwcyui\mvrdjvs.exe
- '10#.#56.25.224':8007
- 'gu##o.xyz':8006
- DNS ASK gu##o.xyz
- ClassName: '4823-00000029' WindowName: ''
- ClassName: '18467-41' WindowName: ''
- '%ProgramFiles(x86)%\microsoft gwcyui\mvrdjvs.exe'
- '%ProgramFiles(x86)%\microsoft gwcyui\mvrdjvs.exe' Win7