Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'DwmHelper' = '%LOCALAPPDATA%\Microsoft\Windows\Themes\dwm_helper.exe'
- <SYSTEM32>\tasks\dwmhelperelevate
- Диспетчера задач (Taskmgr)
- '<SYSTEM32>\taskkill.exe' /F /IM taskmgr.exe
- <Текущая директория>\event.log
- %LOCALAPPDATA%\microsoft\windows\themes\dwm_helper.exe
- %LOCALAPPDATA%\microsoft\windows\themes\dwm_svc.exe
- ClassName: '' WindowName: ''
- '%LOCALAPPDATA%\microsoft\windows\themes\dwm_helper.exe'
- '%LOCALAPPDATA%\microsoft\windows\themes\dwm_svc.exe' --watchdog 5504
- '<SYSTEM32>\schtasks.exe' /create /tn DwmHelperElevate /tr %LOCALAPPDATA%\Microsoft\Windows\Themes\dwm_helper.exe /sc onlogon /rl highest /f