Техническая информация
- [<HKLM>\SOFTWARE\Classes\exefile\shell\open\command] '' = '"<SYSTEM32>\msupdate32.exe" -run "%1" %*'
- [<HKLM>\SOFTWARE\Classes\exefile\shell\open\command] '' = '"%1" %*'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ctfmon.exe' = 'msupdate32.exe -run <SYSTEM32>\ctfmon.exe'
- <SYSTEM32>\noise.bin
- ClassName: 'Indicator' WindowName: ''