Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] 'WebCheck' = '{E6FB5E20-DE35-11CF-9C87-00AA005127ED}'
- '<SYSTEM32>\taskkill.exe' /im egui.exe /f
- '<SYSTEM32>\sc.exe' stop policyagent
- '<SYSTEM32>\sc.exe' delete ekrn
- '<SYSTEM32>\taskkill.exe' /im ekrn.exe /f
- ekrn.exe
- <SYSTEM32>\132921.DEP
- %CommonProgramFiles%\rgdltecq\ohoifz.pif
- ClassName: '(null)' WindowName: '(null)'