Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\uhssvc Services] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\uhssvc Services] 'ImagePath' = '%CommonProgramFiles%\Services\uhssvc.exe'
- 'uhssvc Services' %CommonProgramFiles%\Services\uhssvc.exe
- <SYSTEM32>\svchost.exe
- %TEMP%\rarsfx0\consent.exe
- %TEMP%\rarsfx0\consentloc.dll
- %TEMP%\rarsfx0\consentloc.dll.dat
- %CommonProgramFiles%\services\uhssvc.exe
- %CommonProgramFiles%\services\uhssvcloc.dll
- %TEMP%\rarsfx0\consentloc.dll.dat
- %TEMP%\rarsfx0\consent.exe
- %TEMP%\rarsfx0\consentloc.dll
- %CommonProgramFiles%\services\uhssvcloc.dll
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\rarsfx0\consent.exe'
- '%CommonProgramFiles%\services\uhssvc.exe'
- '<SYSTEM32>\svchost.exe' -k LocalServiceNetworkRestricted' (со скрытым окном)
- '<SYSTEM32>\svchost.exe' -k LocalServiceNetworkRestricted