Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Defender Real-time protection' = '<LS_APPDATA>\Microsoft\Windows\Windows Defender\MSASRui.exe'
- '<LS_APPDATA>\Microsoft\Windows\Windows Defender\MSASRui.exe'
- <LS_APPDATA>\Microsoft\Windows\Windows Defender\setting
- %TEMP%\aut6.tmp
- %TEMP%\dll-305.ico
- <LS_APPDATA>\Microsoft\Windows\Windows Defender\MSASRui.exe
- %TEMP%\aut9.tmp
- %TEMP%\autA.tmp
- %TEMP%\aut7.tmp
- %TEMP%\aut8.tmp
- %TEMP%\aut5.tmp
- %TEMP%\aut2.tmp
- %TEMP%\dll-302.ico
- %TEMP%\aut1.tmp
- %TEMP%\system.pif
- %TEMP%\aut4.tmp
- %TEMP%\dll-304.ico
- %TEMP%\aut3.tmp
- %TEMP%\dll-303.ico
- %TEMP%\dll-305.ico
- %TEMP%\system.pif
- <LS_APPDATA>\Microsoft\Windows\Windows Defender\MSASRui.exe
- %TEMP%\dll-302.ico
- %TEMP%\dll-303.ico
- %TEMP%\dll-304.ico
- %TEMP%\aut7.tmp
- %TEMP%\aut6.tmp
- %TEMP%\aut8.tmp
- %TEMP%\autA.tmp
- %TEMP%\aut9.tmp
- %TEMP%\aut2.tmp
- %TEMP%\aut1.tmp
- %TEMP%\aut3.tmp
- %TEMP%\aut5.tmp
- %TEMP%\aut4.tmp