Техническая информация
- C:\Extracted\Kernel Detective.exe
- C:\Extracted\serverr1.exe
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\Preferred
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\194723e5-787b-412f-ac21-d0afb634bb62
- <DRIVERS>\KeDetective131.sys
- %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\699c4b9cdebca7aaea5193cae8a50098_23ef5514-3059-436f-a4a7-4cefaab20eb1
- C:\Extracted\serverr1.exe
- %TEMP%\sfx.ini
- C:\Extracted\Kernel Detective.exe
- <DRIVERS>\KeDetective131.sys
- %TEMP%\sfx.ini
- ClassName: 'Shell_TrayWnd' WindowName: ''