Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\poison] 'ImagePath' = '<DRIVERS>\G11.sys'
- 'poison' <DRIVERS>\G11.sys
- <SYSTEM32>\securityhealthsystray.exe
- <SYSTEM32>\securityhealthservice.exe
- <DRIVERS>\g11.sys
- %ALLUSERSPROFILE%\microsoft\windows security health\logs\shs-06192026-170142-7-7f-19041.1.amd64fre.vb_release.191206-1406.etl
- '<SYSTEM32>\securityhealthservice.exe'