Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\AdsRemoveV3] 'Start' = '00000002'
- '<SYSTEM32>\ardmv3c4.exe'
- '<SYSTEM32>\net1.exe' start AdsRemoveV3
- %TEMP%\WER45ff.dir00\ardmv3c4.exe.hdmp
- %TEMP%\WER45ff.dir00\ardmv3c4.exe.mdmp
- %TEMP%\WER45ff.dir00\manifest.txt
- %TEMP%\WER45ff.dir00\appcompat.txt
- <SYSTEM32>\libcurl.dll
- <SYSTEM32>\ardmv3c4.exe
- <SYSTEM32>\zlib1.dll
- <SYSTEM32>\ssleay32.dll
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'