Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'msnetobjwow.exe' = '%WINDIR%\msnetobjwow.exe'
- %WINDIR%\msnetobjwow.exe
- <SYSTEM32>\netsh.exe firewall add allowedprogram program="%WINDIR%\msnetobjwow.exe" name="Windows Update Service" mode=ENABLE scope=ALL profile=ALL
- <SYSTEM32>\9DDCC9E44F12B4496310808ED4E11A06\unrar.exe
- %WINDIR%\msnetobjwow.exe
- <SYSTEM32>\9DDCC9E44F12B4496310808ED4E11A06\unrar.exe
- %WINDIR%\msnetobjwow.exe