Техническая информация
- [<HKLM>\SOFTWARE\Classes\exefile\shell\open\command] '' = '"exefile" /shell <%1> %*'
- [<HKLM>\SYSTEM\ControlSet001\Services\userinit] 'ImagePath' = '\\.\globalroot<SYSTEM32>\usеrinit.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\userinit] 'Start' = '00000002'
- Центр обеспечения безопасности (Security Center)
- <SYSTEM32>\usеrinit.exe
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\svchost.exe
- %WINDIR%\Explorer.EXE
- %TEMP%\{E9C1E0AC-C9B1-4c85-94DE-9C1518918D02}.tlb
- %TEMP%\{E9C1E0AC-C9B1-4c85-94DE-9C1518918D01}.tlb
- %ALLUSERSPROFILE%\Application Data\.wtav
- <SYSTEM32>\exefile.exe
- <SYSTEM32>\usеrinit.exe
- <SYSTEM32>\msxmwaej.dll
- '88.##8.21.219':8083
- 'localhost':1041
- '94.##.199.163':8083
- DNS ASK
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'z00clicker' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''