Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'dllhost' = '%WINDIR%Updates\explorer\dllhost.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'RuntimeBroker' = '%WINDIR%Updates\explorer\RuntimeBroker.exe'
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath '%WINDIR%\regedit.exe'
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath '%TEMP%\'
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath '%HOMEPATH%\Desktop'
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath '%WINDIR%Updates'
- %WINDIR%updates\explorer.zip