Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\permchk] 'Startup' = ''
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\permchk] 'DLLName' = 'permchk23.dll'
- <SYSTEM32>\efbd8d37.dll
- <SYSTEM32>\d0392fda.dll
- %TEMP%\0000004f.cab
- <SYSTEM32>\permchk23.dll
- %TEMP%\0000004f.cab