Техническая информация
- [HKLM\System\CurrentControlSet\Services\Rsvfnd ewyewxen] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Rsvfnd ewyewxen] 'ImagePath' = '%ProgramFiles(x86)%\Microsoft Efhbwj\Ogwyiku.exe'
- 'Rsvfnd ewyewxen' %ProgramFiles(x86)%\Microsoft Efhbwj\Ogwyiku.exe
- ClassName: 'Regmonclass', WindowName: ''
- ClassName: 'Filemonclass', WindowName: ''
- %ProgramFiles(x86)%\microsoft efhbwj\ogwyiku.exe
- %ProgramFiles(x86)%\microsoft efhbwj\ogwyiku.exe
- из <Полный путь к файлу> в %WINDIR%\syswow64\874370.bak
- '10#.#2.15.123':80
- '18#.#02.26.193':8000
- ClassName: '4823-00000029' WindowName: ''
- ClassName: '18467-41' WindowName: ''
- '%ProgramFiles(x86)%\microsoft efhbwj\ogwyiku.exe'