Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'intelmain' = 'C:\ProgramData\Intel(R) Management\intelmain.exe'
- 'C:\ProgramData\Intel(R) Management\Starter.exe'
- 'C:\ProgramData\Intel(R) Management\intelmain.exe'
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 348
- '<SYSTEM32>\wscript.exe' "C:\ProgramData\Intel(R) Management\start1.vbs"
- C:\ProgramData\Intel(R) Management\start1.vbs
- %TEMP%\dw.log
- %TEMP%\1D387.dmp
- C:\ProgramData\Intel(R) Management\Starter.exe
- C:\ProgramData\Intel(R) Management\intelmain.exe
- C:\ProgramData\Intel(R) Management\intelservise.exe
- C:\ProgramData\Intel(R) Management\killer.exe
- C:\ProgramData\Intel(R) Management\intelmain.exe
- ClassName: 'EDIT' WindowName: ''