Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\kungsfbaqjgocb] 'start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\svjqvnngxcxbvoqm] 'start' = '00000001'
- '<SYSTEM32>\spoolsv.exe'
- <DRIVERS>\svjqvnngxcxbvoqm.sys
- <DRIVERS>\kungsfordlsfyx.sys
- %TEMP%\yfvitusiem.tmp
- %TEMP%\coiqhxbdwo.tmp