Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\PROCEXP113] 'Start' = '00000001'
- [HKLM\SYSTEM\CurrentControlSet\Services\PROCEXP113] 'ImagePath' = '<DRIVERS>\PROCEXP113.SYS'
- %WINDIR%\write.exe
- <DRIVERS>\procexp113.sys
- %WINDIR%\debug\dslt.log
- '%WINDIR%\write.exe'