Техническая информация
- %WINDIR%\svchost.exe /s sogou.reg
- %WINDIR%\svchost.exe
- %TEMP%\bt1248.bat
- %TEMP%\bt1248.bat
- <SYSTEM32>\dllcache\svchost.exe
- %TEMP%\bt1248.bat
- %WINDIR%\svchost.exe
- <SYSTEM32>\svchost.exe
- ClassName: 'RegEdit_RegEdit' WindowName: ''