Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ntmsevt32] 'Startup' = 'S'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ntmsevt32] 'DLLName' = 'ntmsevt32.dll'
- <SYSTEM32>\456278c0.dll
- <SYSTEM32>\ntmsevt32.dll
- <SYSTEM32>\3fd26e99.dll