Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\EFS] 'Start' = '00000002'
- %WINDIR%\syswow64\diskraid.exe
- 64bitmapibroker.exe
- %WINDIR%\prefetch\cmd.exe-4a81b364.pf
- %WINDIR%\prefetch\aspnet_regiis.exe-b76f1ad7.pf
- %WINDIR%\prefetch\regedit.exe-90feea06.pf
- %WINDIR%\prefetch\regsvcs.exe-a54ad617.pf
- %WINDIR%\prefetch\regtlib.exe-e21980a2.pf
- %WINDIR%\prefetch\schtasks.exe-5ca45734.pf
- '%WINDIR%\syswow64\diskraid.exe' {"variant":4,"path":"C:\\qattja\\<Имя файла>.exe","processid":2280,"uid":"0593a4d57ed267d552c8cd0d0bce128e"}