Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'System' = '<SYSTEM32>\run.com'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{TEST_9381D8F2-0288-11D0-9501-00AA00B911A5}] 'StubPath' = '<SYSTEM32>\spool.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'shell' = 'Explorer.exe winsock.scr'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'winupde' = '%WINDIR%\mwspool.exe'
- <SYSTEM32>\run.com
- <SYSTEM32>\spool.exe
- %WINDIR%\winsock.scr
- %WINDIR%\mwspool.exe