Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Updater' = '%WINDIR%\shost.exe'
- %WINDIR%\shost.exe
- <SYSTEM32>\ntvdm.exe -f -i1
- <SYSTEM32>\loa.exe
- <SYSTEM32>\qw.dat
- %WINDIR%\shost.exe
- ClassName: 'Indicator' WindowName: ''