Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe] 'Debugger' = '<SYSTEM32>\dllcache\svcchost.exe'
- '<DRIVERS>\svchost.exe'
- '<SYSTEM32>\dllcache\svcchost.exe'
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\MSWINSCK.OCX
- <SYSTEM32>\dllcache\wiascrs.dll
- <DRIVERS>\svchost.exe
- <SYSTEM32>\dllcache\svcchost.exe