Техническая информация
- <SYSTEM32>\tasks\windowsconfigupdate
- %WINDIR%\microsoft.net\framework64\v4.0.30319\regasm.exe
- %APPDATA%\microsoft\windows\explorer\explorer_plugin.exe
- %TEMP%\content\4812-3876-regasm.exe-22-08-48-734.dump
- '%APPDATA%\microsoft\windows\explorer\explorer_plugin.exe'
- '<SYSTEM32>\schtasks.exe' /create /tn "WindowsConfigUpdate" /tr "%APPDATA%\Microsoft\Windows\Explorer\explorer_plugin.exe" /sc onlogon /f /rl highest
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\regasm.exe'