Техническая информация
- [HKLM\System\CurrentControlSet\Services\TaskKill] 'Start' = '00000000'
- [HKLM\System\CurrentControlSet\Services\TaskKill] 'ImagePath' = '%TEMP%\Иисус.sys'
- 'TaskKill' %TEMP%\Иисус.sys
- %WINDIR%\microsoft.net\framework64\v4.0.30319\jsc.exe
- %WINDIR%\microsoft.net\framework64\v4.0.30319\installutil.exe
- %WINDIR%\microsoft.net\framework64\v4.0.30319\aspnet_compiler.exe
- %WINDIR%\microsoft.net\framework64\v4.0.30319\edmgen.exe
- %WINDIR%\microsoft.net\framework64\v4.0.30319\applaunch.exe
- %WINDIR%\microsoft.net\framework64\v4.0.30319\csc.exe
- %WINDIR%\microsoft.net\framework64\v4.0.30319\ilasm.exe
- %WINDIR%\microsoft.net\framework64\v4.0.30319\aspnet_regsql.exe
- %WINDIR%\microsoft.net\framework64\v4.0.30319\addinprocess.exe
- %TEMP%\иисус.sys
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\jsc.exe'