Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemihxmi.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemtfbpi.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqempdmkg.exe'
- '%TEMP%\Sysqemihxmi.exe'
- '%TEMP%\Sysqemtfbpi.exe'
- '%TEMP%\Sysqempdmkg.exe'
- %TEMP%\Sysqemtfbpi.exe
- %TEMP%\Sysqemihxmi.exe
- %TEMP%\Sysqempdmkg.exe
- %TEMP%\qpath.ini
- %TEMP%\Sysqamqqvaqqd.exe
- %TEMP%\Sysqemtfbpi.exe
- %TEMP%\Sysqemihxmi.exe
- %TEMP%\Sysqempdmkg.exe
- %TEMP%\Sysqamqqvaqqd.exe