Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\SystemNotification] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\SystemNotification] 'ImagePath' = '%ALLUSERSPROFILE%\System\SystemNotification.exe'
- 'SystemNotification' %ALLUSERSPROFILE%\System\SystemNotification.exe
- Журнал событий Windows (Windows Event Logging)
- <SYSTEM32>\conhost.exe
- %ALLUSERSPROFILE%\system\systemnotification.exe
- %WINDIR%\temp\afpkidpwzzav.sys
- DNS ASK gu##.##neroocean.stream
- '%ALLUSERSPROFILE%\system\systemnotification.exe'
- '<SYSTEM32>\powercfg.exe' /x -hibernate-timeout-ac 0
- '<SYSTEM32>\powercfg.exe' /x -hibernate-timeout-dc 0
- '<SYSTEM32>\powercfg.exe' /x -standby-timeout-ac 0
- '<SYSTEM32>\powercfg.exe' /x -standby-timeout-dc 0
- '<SYSTEM32>\sc.exe' delete "SystemNotification"
- '<SYSTEM32>\sc.exe' create "SystemNotification" binpath= "%ALLUSERSPROFILE%\System\SystemNotification.exe" start= "auto"
- '<SYSTEM32>\sc.exe' stop eventlog
- '<SYSTEM32>\sc.exe' start "SystemNotification"