Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\wscntfyservc] 'Start' = '00000002'
- %CommonProgramFiles%\MSSecurity\wscntfy.exe -run
- <SYSTEM32>\sethc.exe
- %CommonProgramFiles%\MSSecurity\wscntfy.exe
- %TEMP%\c1.tmp.new
- %CommonProgramFiles%\MSSecurity\wscntfy.ocx
- %TEMP%\perlib_3432435.tmp
- %CommonProgramFiles%\MSSecurity\icon.dat
- %TEMP%\perlib_3432435.tmp