Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\msdlsdws] 'Start' = '00000002'
- %PROGRAM_FILES%\Windows NT\Accessories\nt\lsass.exe
- <SYSTEM32>\cmd.exe /c %TEMP%\nfnegd.bat
- <SYSTEM32>\lsass.exe
- %TEMP%\nfnegd.bat
- %PROGRAM_FILES%\Windows NT\Accessories\nt\lsass.exe