Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'Explorer.exe commamd.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ctfnom.exe' = '%WINDIR%\SVOHOST.exe'
- [<HKLM>\SOFTWARE\Classes\exefile\shell\open\command] '' = '<SYSTEM32>\he1p.exe "%1" %*'
- скрытых файлов
- '%WINDIR%\SVOHOST.exe'
- %WINDIR%\ГАЕ®ј¤Зйґу±©№в.RM.exe
- %WINDIR%\їґµГИГИЛёР¶ЇµДБчАбµД¶Ї».RM.exe
- %WINDIR%\ёЯЗеОъГАЕ®ВјПс.RM.exe
- %WINDIR%\ѕшЙ«ЗгіЗMMРг.RM.exe
- %WINDIR%\ГАЕ®·ўПЦ±»НµЕДєуЈ¬ѕ№И»ЧціцИзґЛј¤БТµД·ґУ¦.RM.exe
- %WINDIR%\ДгЧоПлТЄµД¶«¶«.RM.exe
- %WINDIR%\ЧоРВЛўЧ°±ёЅМіМ,ЛщУРНшВзУОП·НЁУГ.RM.exe
- <SYSTEM32>\lsasa.exe
- <SYSTEM32>\commamd.exe
- %WINDIR%\SVOHOST.exe
- <SYSTEM32>\he1p.exe
- %WINDIR%\ИГГАЕ®К§Й«µДМ©№ъИЛСэII.RM.exe
- %WINDIR%\ЧоРВЛўQ±Т¶Ї»ЅМіМ.RM.exe
- %WINDIR%\№гЦЭДієЅїХ№«ЛѕMMѕьСµХХЖ¬.RM.exe
- <SYSTEM32>\he1p.exe
- <SYSTEM32>\lsasa.exe
- ClassName: 'RichEdit20A' WindowName: '(null)'
- ClassName: '#32770' WindowName: '(null)'
- ClassName: 'AfxWnd42' WindowName: '(null)'
- ClassName: 'Button' WindowName: '????(&S)'
- ClassName: 'RICHEDIT' WindowName: '(null)'
- ClassName: 'soft' WindowName: 'win9x'
- ClassName: 'Indicator' WindowName: '(null)'
- ClassName: 'ddqxyz' WindowName: 'joyiex'
- ClassName: 'ThunderRT6FormDC' WindowName: 'Windows ??????????'
- ClassName: '(null)' WindowName: '(null)'