Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{0cb69fff-0b12-11e1-b22f-806d6172696f}] 'StubPath' = '%ALLUSERSPROFILE%\Application Data\slsvc.exe -r'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'Intel® Platform Technology Client ' = '%CommonProgramFiles%\systray.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Microsoft Software Licensing Service' = '%ALLUSERSPROFILE%\Application Data\slsvc.exe'
- скрытых файлов
- Средство контроля пользовательских учетных записей (UAC)
- %CommonProgramFiles%\systray.exe
- %ALLUSERSPROFILE%\Application Data\slsvc.exe
- %CommonProgramFiles%\systray.exe
- %TEMP%\dw.log
- %TEMP%\22996.dmp
- <SYSTEM32>\systemant.exe
- <SYSTEM32>\Microsoft\Protect\S-1-5-18\51232717-fb3f-414f-add0-1591d7dab40a
- <SYSTEM32>\Microsoft\Protect\S-1-5-18\Preferred
- %ALLUSERSPROFILE%\Application Data\slsvc.exe
- %CommonProgramFiles%\systray.exe
- %ALLUSERSPROFILE%\Application Data\slsvc.exe
- ClassName: 'Shell_TrayWnd' WindowName: ''