Техническая информация
- [<HKLM>\SYSTEM\ControlSet002\Services\Defender] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet002\Services\Defender] 'ImagePath' = '%WINDIR%\appdata\nssm.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Defender] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\Defender] 'ImagePath' = '%WINDIR%\appdata\nssm.exe'
- %WINDIR%\appdata\svchost.exe
- %WINDIR%\appdata\msvcr120.dll
- %WINDIR%\appdata\nssm.exe
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- ClassName: 'Shell_TrayWnd' WindowName: ''