Техническая информация
- '<SYSTEM32>\wscript.exe' "%WINDIR%\install.vbs"
- '<SYSTEM32>\wscript.exe' "%WINDIR%\guard.vbs"
- '%WINDIR%\guard.exe' e -pg5d8f7w7e
- %WINDIR%\driver.exe
- %WINDIR%\install.vbs
- %WINDIR%\guard.vbs
- %WINDIR%\guard.exe
- %WINDIR%\driver.exe
- %WINDIR%\install.vbs
- %WINDIR%\guard.vbs
- %WINDIR%\guard.exe
- %WINDIR%\driver.exe
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''