Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Control\Print\Providers\GMY931m9.dll] 'Name' = '<SYSTEM32>\spool\PRTPROCS\W32X86\GMY931m9.dll'
- [<HKLM>\SYSTEM\ControlSet001\Services\k17gM1gM.sys] 'imagepath' = '%WINDIR%\TEMP\k17gM1gM.sys'
- [<HKLM>\SYSTEM\ControlSet001\Services\k17gM1gM.sys] 'start' = '00000001'
- <SYSTEM32>\spoolsv.exe
- %WINDIR%\Temp\k17gM1gM.sys
- <SYSTEM32>\spool\prtprocs\w32x86\GMY931m9.dll
- из <Полный путь к вирусу> в %TEMP%\EIQG7i3