Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Task Manager' = '%APPDATA%\Windows Task Manager\taskmgr.exe'
- '%APPDATA%\Windows Task Manager\taskmgr.exe'
- '<SYSTEM32>\dumprep.exe' 2876 -dm 7 7 %TEMP%\WERb57c.dir00\taskmgr.exe.hdmp 16325836412027280
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\sysdm.cpl,NoExecuteProcessException %APPDATA%\Windows Task Manager\taskmgr.exe
- '<SYSTEM32>\dumprep.exe' 2876 -dm 7 7 %TEMP%\WERb57c.dir00\taskmgr.exe.mdmp 16325836412027260
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\.bat" "
- '<SYSTEM32>\reg.exe' ADD "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "Windows Task Manager" /t REG_SZ /d "%APPDATA%\Windows Task Manager\taskmgr.exe" /f
- %TEMP%\WERb57c.dir00\taskmgr.exe.hdmp
- %TEMP%\WERb57c.dir00\appcompat.txt
- %TEMP%\WERb57c.dir00\manifest.txt
- %TEMP%\.bat
- %APPDATA%\Windows Task Manager\taskmgr.exe
- %TEMP%\WERb57c.dir00\taskmgr.exe.mdmp
- %TEMP%\.bat
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'Indicator' WindowName: '(null)'