Техническая информация
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'cftmon' = '<SYSTEM32>\cftmon.exe'
- [<HKLM>\System\CurrentControlSet\Services\WMOptimizer] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\WMOptimizer] 'ImagePath' = '<SYSTEM32>\scvhost.exe service'
- 'WMOptimizer' <SYSTEM32>\scvhost.exe service
- %WINDIR%\syswow64\scvhost.exe
- %WINDIR%\syswow64\cftmon.exe
- %WINDIR%\syswow64\scvhost.exe
- %WINDIR%\syswow64\cftmon.exe
- '%WINDIR%\syswow64\scvhost.exe' service