Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Safewe_Client' = '"<SYSTEM32>\barguard\SafeWe_Client.exe" -start'
- <SYSTEM32>\barguard\SafeWe_Client.exe -start
- <SYSTEM32>\barguard\SafeWe_Client.exe
- <DRIVERS>\SafeweKernel.sys
- ClassName: 'MS_WINHELP' WindowName: ''