Техническая информация
- [<HKLM>\SYSTEM\ControlSet003\Services\sytem] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet002\Services\sytem] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\sytem] 'Start' = '00000002'
- '<SYSTEM32>\svchost.exe' -k sytem
- <DRIVERS>\sytem.SYS
- <SYSTEM32>\sytem.dll