Техническая информация
- [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'run' = '<SYSTEM32>\recovery.exe'
- <SYSTEM32>\recovery.exe
- C:\kms\kms_vl_all_aio.cmd
- C:\kms\kms_vl_all_aio_debug.log
- C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\office32ww.msi
- C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\office32ww.xml
- C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\owow32ww.cab
- C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\pkeyconfig-office.xrm-ms