Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\Host Generic Process] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Host Generic Process] 'ImagePath' = '<DRIVERS>\svchost.exe'
- cvtres.exe
- %TEMP%\cvtres.exe
- %WINDIR%\syswow64\drivers\svchost.exe
- '%TEMP%\cvtres.exe'
- '%WINDIR%\syswow64\drivers\svchost.exe'