Техническая информация
- [HKLM\System\CurrentControlSet\Services\KProcessHacker3] 'ImagePath' = '%TEMP%\IXP000.TMP\kprocesshacker.sys'
- 'KProcessHacker3' %TEMP%\IXP000.TMP\kprocesshacker.sys
- %TEMP%\ixp000.tmp\kprocesshacker.sys
- %TEMP%\ixp000.tmp\peview.exe
- %TEMP%\ixp000.tmp\processhacker.exe
- %TEMP%\ixp000.tmp\processhacker.sig
- %WINDIR%\temp\udd2e8e.tmp
- %WINDIR%\temp\udd2e8e.tmp
- ClassName: 'ProcessHacker' WindowName: ''
- '%TEMP%\ixp000.tmp\processhacker.exe'