Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Mnopqr Tuvwxyab Def] 'ImagePath' = '<SYSTEM32>\mmqcmg.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Mnopqr Tuvwxyab Def] 'Start' = '00000002'
- '<SYSTEM32>\wscript.exe' "C:\8590.vbs"
- '%TEMP%\is-QBMAI.tmp\IWan968Install.tmp' /SL5="$40092,11697774,151552,%WINDIR%\inf\IWan968Install.exe"
- '<SYSTEM32>\mmqcmg.exe'
- '%WINDIR%\inf\iwan968.exe'
- '%WINDIR%\inf\IWan968Install.exe'
- %TEMP%\is-6JO3A.tmp\_isetup\_shfoldr.dll
- <SYSTEM32>\mmqcmg.exe
- C:\8590.vbs
- %WINDIR%\inf\IWan968Install.exe
- %WINDIR%\inf\iwan968.exe
- %TEMP%\is-QBMAI.tmp\IWan968Install.tmp
- C:\8590.vbs
- %WINDIR%\inf\iwan968.exe
- '11#####10.paobbb.com':50128
- DNS ASK 11#####10.paobbb.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''