Техническая информация
- '%WINDIR%\syswow64\reg.exe' EXPORT HKCU\Software\Microsoft\Office\16.0\Excel\Security C:\Users\Public\ceI.reg /y
- <SYSTEM32>\csrss.exe
- C:\users\public\zf7hvyzy.dat
- %TEMP%\reg70b7.tmp
- C:\users\public\cei.reg
- %ProgramFiles%\UNP\Logs\UpdateNotificationPipeline.001.etl
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- '<SYSTEM32>\unp\updatenotificationmgr.exe'
- '<SYSTEM32>\apphostregistrationverifier.exe'
- '%ProgramFiles(x86)%\microsoft office\office16\excel.exe' /dde
- '<SYSTEM32>\devicecensus.exe' UserCxt
- '<SYSTEM32>\svchost.exe' -k netsvcs -p