Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] 'Update Windows' = '{8442372B-17FA-167F-8948-B3B4118D42Bf}'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%windir%\explorer.exe' = '%windir%\explorer.exe:*:enabled:Shell update server connection'
- <SYSTEM32>\update.dll
- C:\pagefile.dat
- C:\pagefile.dat