Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\UpdateUtility] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\UpdateUtility] 'ImagePath' = '<SYSTEM32>\svchost.exe -k UpdateGroup'
- [HKLM\SYSTEM\CurrentControlSet\Services\UpdateUtility\Parameters] 'ServiceDll' = '%WINDIR%\ntshrui.dll'
- 'UpdateUtility' <SYSTEM32>\svchost.exe -k UpdateGroup
- %WINDIR%\ntshrui.dll
- '<SYSTEM32>\svchost.exe' -k UpdateGroup -s UpdateUtility