Техническая информация
- [HKLM\System\CurrentControlSet\Services\Rsiswk gseskmim] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Rsiswk gseskmim] 'ImagePath' = '%WINDIR%\Yiamqq.exe -svc'
- 'Rsiswk gseskmim' %WINDIR%\Yiamqq.exe -svc
- <SYSTEM32>\conhost.exe
- C:\source\loader.txt
- C:\source\kernel.txt
- C:\users\public\documents\netuser.tmp
- <SYSTEM32>\ini.ini
- %WINDIR%\yiamqq.exe
- %WINDIR%\yiamqq.exe
- '%WINDIR%\yiamqq.exe' -svc