Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Startup' = '"<SYSTEM32>\fwsvc.exe" jxb'
- %WINDIR%\Tasks\Watchmonn Service.job
- '<SYSTEM32>\idfs.exe' 3je3
- %ALLUSERSPROFILE%\Documents\ntuser{4ADC783F-6712-9832-8698-FFFFFFFF70AA0201}.pol
- %ALLUSERSPROFILE%\Documents\ntuser{4ADC783F-6712-9832-8698-FFFFFFFF70141501}.pol
- %ALLUSERSPROFILE%\Documents\ntuser{4ADC783F-6712-9832-8698-FFFFFFFF80A5F801}.pol
- <SYSTEM32>\idfs.exe
- <SYSTEM32>\fwsvc.exe
- %ALLUSERSPROFILE%\Documents\ntuser{4ADC783F-6712-9832-8698-E42EDD6270941101}.pol