Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\lqhexts] 'Startup' = 'WLEventStartup'
- %ALLUSERSPROFILE%\Application Data\Microsoft\MSIDL\~EFD817520595.tmp
- %ALLUSERSPROFILE%\Application Data\Microsoft\MSIDL\~EFD3019420592.tmp
- <SYSTEM32>\Setup\lqhexts.dll
- %ALLUSERSPROFILE%\Application Data\Microsoft\MSIDL\~EFD817520595.tmp
- %ALLUSERSPROFILE%\Application Data\Microsoft\MSIDL\~EFD3019420592.tmp