Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] 'LoadAppInit_DLLs' = '00000001'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] 'AppInit_DLLs' = 'C:\PROGRA~2\Mozilla\qfczndm.dll'
- '<SYSTEM32>\taskeng.exe' {B4E6A26A-7BB9-4A4B-9A25-63FBFBFA2ED6} S-1-5-18:NT AUTHORITY\System:Service:
- C:\ProgramData\Mozilla\qfczndm.dll
- C:\ProgramData\Mozilla\kymymkk.exe
- <SYSTEM32>\Tasks\tewyshn