Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '' = '%WINDIR%\twain_32\rwrlw00219HC.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\JieBa] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\JieBa] 'ImagePath' = '%ProgramFiles%\Winjieba\JieBa.sys'
- '%WINDIR%\regedit.exe' /s c:\reg.reg
- '<SYSTEM32>\cmd.exe' /c regedit /s c:\reg.reg
- '<SYSTEM32>\odbcad32.exe'
- <SYSTEM32>\odbcad32.exe
- %WINDIR%\twain_32\rwrlw00219HC.exe
- %WINDIR%\lj.ini
- %WINDIR%\twain_32\dlcore.dll
- C:\reg.reg
- %WINDIR%\lj.ini
- ClassName: 'RegEdit_RegEdit' WindowName: ''