Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'StubPath' = '"C:\Setup\CacheMgr.exe" -as'
- [<HKLM>\System\CurrentControlSet\Services\eventchk] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\eventchk] 'ImagePath' = '<SYSTEM32>\inf\svchost.exe'
- [<HKLM>\system\controlset001\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] '<SYSTEM32>\inf\svchost.exe' = '<SYSTEM32>\inf\svchost.exe:*:Enabled:@x...
- %WINDIR%\syswow64\inf\svchost.exe
- C:\setup\cachemgr.exe
- %WINDIR%\syswow64\inf\svchost.exe
- '%WINDIR%\syswow64\inf\svchost.exe'
- 'C:\setup\cachemgr.exe' -as
- '%WINDIR%\syswow64\cmd.exe' /q /c md "C:\Setup"
- '%WINDIR%\syswow64\cmd.exe' /q /c copy "<Полный путь к файлу>" "C:\Setup\CacheMgr.exe"