Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Spooler] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\WinServerView] 'Start' = '00000002'
- '<SYSTEM32>\sys_temtray.exe'
- '<SYSTEM32>\cmd.exe' /c c:\del.bat
- '<SYSTEM32>\net1.exe' start WinServerView
- '<SYSTEM32>\sc.exe' create WinServerView binpath= "<SYSTEM32>\sys_temtray.exe" type= share start= auto displayname= "systemtray" depend= RPCSS/Tcpip/IPSec
- <SYSTEM32>\spoolsv.exe
- C:\del.bat
- <SYSTEM32>\sys_temtraykaba.sub
- <SYSTEM32>\sys_temtray.txt
- <SYSTEM32>\sys_temtray.jpg
- <SYSTEM32>\hz_sys_temtray.dll
- <SYSTEM32>\sys_temtray.exe
- <SYSTEM32>\sys_temtray.ini
- <SYSTEM32>\hz_sys_temtray.dat
- <SYSTEM32>\keyHook.dll
- <SYSTEM32>\sys_temtray.exe
- <SYSTEM32>\sys_temtray.ini
- <SYSTEM32>\hz_sys_temtray.dat
- '<IP-адрес в локальной сети>':8760
- ClassName: 'MS_WINHELP' WindowName: ''