Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\hy5.7] 'ImagePath' = '%TEMP%\aYYABi0.sys'
- '<SYSTEM32>\cmd.exe'
- <SYSTEM32>\cmd.exe
- <SYSTEM32>\cmd.exe
- %TEMP%\aYYABi0.sys
- C:\bfdl.txt
- %TEMP%\aYYABi0.sys
- %TEMP%\aYYABi0.sys
- ClassName: '' WindowName: '<Имя вируса>.exe'