Техническая информация
- [<HKLM>\SOFTWARE\Classes\txtfile\shell\open\command] '' = '<DRIVERS>\sysdrv.exe %1'
- [<HKCU>\Control Panel\Desktop] 'SCRNSAVE.EXE' = '<SYSTEM32>\winlogon.scr'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'main' = '<DRIVERS>\sysdrv.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'default' = '%HOMEPATH%\scvhost.exe'
- <SYSTEM32>\winlogon.scr
- %HOMEPATH%\scvhost.exe
- <DRIVERS>\sysdrv.exe
- %HOMEPATH%\scvhost.exe
- <DRIVERS>\sysdrv.exe
- ClassName: 'Indicator' WindowName: ''