Техническая информация
- %WINDIR%\explorer.exe
- C:\users\public\wfh.dat
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\jthfh2ut\windows-app-web-link[1].json
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\dqs5vvls\windows-app-web-link[1].json
- %ProgramFiles%\UNP\Logs\UpdateNotificationPipeline.001.etl
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- '%ProgramFiles(x86)%\microsoft office\office16\excel.exe' /dde
- '<SYSTEM32>\devicecensus.exe' UserCxt
- '<SYSTEM32>\svchost.exe' -k netsvcs -p