Техническая информация
- [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemfvhxu.exe'
- %TEMP%\qpath.ini
- %TEMP%\sysqamqqvaqqd.exe
- %TEMP%\sysqemfvhxu.exe
- %TEMP%\sysqemfvhxu.exe
- %TEMP%\sysqamqqvaqqd.exe
- '<DNS_SERVER>':53
- '%TEMP%\sysqemfvhxu.exe'