Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'Explorer.exe'
- '<SYSTEM32>\taskkill.exe' /f /im taskmgr.exe
- '%WINDIR%\explorer.exe'
- '<SYSTEM32>\taskkill.exe' /f /im 3910k9f039k10903k3s17s7.exe
- '<SYSTEM32>\taskkill.exe' /f /im regedit.exe
- '<SYSTEM32>\taskkill.exe' /f /im explorer.exe
- '<SYSTEM32>\taskmgr.exe'
- '%WINDIR%\regedit.exe'
- %WINDIR%\Explorer.EXE
- [<HKLM>\SOFTWARE\Microsoft\MessengerService]
- ClassName: '' WindowName: 'Windows Task Manager'
- ClassName: '' WindowName: '???????? ???????'
- ClassName: '' WindowName: '????????? ????? Windows'
- ClassName: 'SysListView32' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: '' WindowName: '7'
- ClassName: 'Winock' WindowName: ''
- ClassName: 'Winlock' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: 'sound'
- ClassName: '' WindowName: 'WinLock by DOC Hyli'
- ClassName: '' WindowName: 'Winlock'