Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\tjwprw] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\pvsnjv] 'Start' = '00000002'
- <SYSTEM32>\sc.exe create tjwprw type= kernel start= auto binpath= "%PROGRAM_FILES%\Uninstall Information\{a4e16324-d1e9-4f3e-0096-36d69232afaf}\tjwprw.bin"
- <SYSTEM32>\sc.exe create pvsnjv type= kernel binpath= "%PROGRAM_FILES%\Uninstall Information\{a4e16324-d1e9-4f3e-0096-36d69232afaf}\pvsnjv.bin" start= auto
- %WINDIR%\Web\zb7108.htt
- %WINDIR%\srchasst\vpo7506
- %PROGRAM_FILES%\Uninstall Information\{a4e16324-d1e9-4f3e-0096-36d69232afaf}\tjwprw.bin
- %WINDIR%\system\nm6873.drv
- %WINDIR%\inf\zc3825.PNF
- %TEMP%\1.tmp
- %WINDIR%\msapps\zeh3396.nfo
- %WINDIR%\Temp\{a8fc123e-bcde-416b-0098-80fc2fb5edba}
- %PROGRAM_FILES%\Uninstall Information\{a4e16324-d1e9-4f3e-0096-36d69232afaf}\pvsnjv.bin
- %PROGRAM_FILES%\Uninstall Information\{a4e16324-d1e9-4f3e-0096-36d69232afaf}\tjwprw.bin
- %WINDIR%\Temp\{a8fc123e-bcde-416b-0098-80fc2fb5edba}
- %PROGRAM_FILES%\Uninstall Information\{a4e16324-d1e9-4f3e-0096-36d69232afaf}\pvsnjv.bin
- %TEMP%\1.tmp
- DNS ASK www.ba##u.com
- ClassName: 'Shell_TrayWnd' WindowName: ''