Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'AtlasFilesMap1' = '%ALLUSERSPROFILE%\AtlasFilesMap1\rekeywiz.exe'
- <SYSTEM32>\tasks\updateservice
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "UpdateService" /sc once /tr "%ALLUSERSPROFILE%\AtlasFilesMap1\rekeywiz.exe" /st 04:23
- %WINDIR%\explorer.exe
- %TEMP%\1.a
- %ALLUSERSPROFILE%\atlasfilesmap1\rekeywiz.exe
- %ALLUSERSPROFILE%\atlasfilesmap1\duser.dll
- %ALLUSERSPROFILE%\atlasfilesmap1\zu9rysc.tmp
- %ALLUSERSPROFILE%\atlasfilesmap1\rekeywiz.exe.config
- %LOCALAPPDATA%\microsoft\clr_v2.0_32\usagelogs\eqnedt32.exe.log
- <Текущая директория>\~wrd0000.tmp
- <Текущая директория>\~wrl0001.tmp
- <Текущая директория>\~wrl0001.tmp
- %ProgramFiles%\UNP\Logs\UpdateNotificationPipeline.001.etl
- '%CommonProgramFiles(x86)%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '<SYSTEM32>\devicecensus.exe' UserCxt
- '<SYSTEM32>\svchost.exe' -k PrintWorkflow
- '<SYSTEM32>\svchost.exe' -k netsvcs -p