Техническая информация
- '<SYSTEM32>\nxprun.exe'
- '<SYSTEM32>\sc.exe' config MSiSCSI start= disabled
- '<SYSTEM32>\sc.exe' stop MSiSCSI
- '<SYSTEM32>\sc.exe' start AuxNxpSvc
- '<SYSTEM32>\sc.exe' delete nzHxDSvc
- '<SYSTEM32>\sc.exe' stop nzHxDSvc
- '%WINDIR%\explorer.exe'
- '<SYSTEM32>\rundll32.exe' /u <SYSTEM32>\exmon.dll
- '<SYSTEM32>\sc.exe' stop AuxNxpSvc
- '<SYSTEM32>\regsvr32.exe' <SYSTEM32>\exmon.dll /s /u
- %WINDIR%\Explorer.EXE
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoViewOnDrive' = '00040000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoDrives' = '00040000'
- <SYSTEM32>\exmon.dll
- %TEMP%\aut5.tmp
- <SYSTEM32>\nznotify.dll
- %TEMP%\aut6.tmp
- <SYSTEM32>\LDK5AUX.BIN
- %TEMP%\aut7.tmp
- <SYSTEM32>\concpl.cpl
- %TEMP%\aut2.tmp
- %TEMP%\fstpeza
- %TEMP%\aut1.tmp
- <SYSTEM32>\NxpAuxSvc.exe
- %TEMP%\aut4.tmp
- <SYSTEM32>\nxprun.exe
- %TEMP%\aut3.tmp
- %TEMP%\aut5.tmp
- %TEMP%\aut4.tmp
- %TEMP%\aut7.tmp
- %TEMP%\aut6.tmp
- %TEMP%\fstpeza
- %TEMP%\aut1.tmp
- %TEMP%\aut3.tmp
- %TEMP%\aut2.tmp
- ClassName: 'CSCHiddenWindow' WindowName: ''
- ClassName: 'SystemTray_Main' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Proxy Desktop' WindowName: ''
- ClassName: 'SysListView32' WindowName: ''
- ClassName: 'BaseBar' WindowName: 'ChanApp'