Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Services' = '%WINDIR%\services.exe'
- '%WINDIR%\services.exe'
- %TEMP%\~DFAEDED63CB16CE811.TMP
- <SYSTEM32>\Memory.dll
- <SYSTEM32>\Generictest.dll
- %TEMP%\~DFA7D79CE5461906F2.TMP
- %WINDIR%\services.exe
- %TEMP%\~DFA7D79CE5461906F2.TMP