Техническая информация
- [<HKCU>\Software\Microsoft\Active Setup\Installed Components\{FDABBD60-98EE-FABE-DAFF-D6B6D59AFFFC}] 'StubPath' = '%APPDATA%\Keygen.exe'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{FDABBD60-98EE-FABE-DAFF-D6B6D59AFFFC}] 'StubPath' = '%APPDATA%\Keygen.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'rundll32' = '%TEMP%\rundll32 .exe'
- %TEMP%\winamp\svhost.exe
- <SYSTEM32>\windows utlimate.exe
- <SYSTEM32>\KeygenCr.exe
- %TEMP%\winamp\svhost.exe
- %APPDATA%\Keygen.exe
- %TEMP%\rundll32 .exe
- <SYSTEM32>\KeygenCr.exe
- <SYSTEM32>\windows utlimate.exe
- %TEMP%\winamp\svhost.exe
- %TEMP%\rundll32 .exe
- ClassName: 'Shell_TrayWnd' WindowName: ''