Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\aec] 'ImagePath' = '<DRIVERS>\aec.sys'
- <DRIVERS>\asyncmac.sys
- '<SYSTEM32>\cmd.exe' /c sc config avp start= disabled
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\test.tt testall
- '<SYSTEM32>\sc.exe' config avp start= disabled
- '<SYSTEM32>\taskkill.exe' /im avp.exe /f
- '<SYSTEM32>\cmd.exe' /c taskkill.exe /im egui.exe /f
- '<SYSTEM32>\cmd.exe' /c taskkill.exe /im ekrn.exe /f
- '<SYSTEM32>\taskkill.exe' /im egui.exe /f
- '<SYSTEM32>\taskkill.exe' /im ekrn.exe /f
- AVP.EXE
- <DRIVERS>\aec.sys
- <DRIVERS>\asyncmac.sys.new
- %TEMP%\xx1.tmp
- <SYSTEM32>\test.tt
- <SYSTEM32>\1l1.dll
- <DRIVERS>\asyncmac.sys
- %TEMP%\xx1.tmp
- <DRIVERS>\aec.sys
- ClassName: '' WindowName: ''