Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Live Guards' = '%PROGRAM_FILES%\winlogon.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windows Live Guards' = '%PROGRAM_FILES%\winlogon.exe'
- %PROGRAM_FILES%\winlogon.exe
- <SYSTEM32>\winlogon.exe
- %APPDATA%\google_q77[s4-2]rh_h.tmp
- %WINDIR%\pchealth\ERRORREP\UserDumps\winlogon.exe.20110929-153342-00.hdmp
- %WINDIR%\pchealth\ERRORREP\UserDumps\winlogon.exe.20110929-153342-00.mdmp
- %TEMP%\Bjg6c8hIE.txt
- %PROGRAM_FILES%\winlogon.exe
- %PROGRAM_FILES%\winlogon.exe
- 'se#####eiro.sytes.net':7349
- DNS ASK se#####eiro.sytes.net
- '<IP-адрес в локальной сети>':1033
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'ConsoleWindowClass' WindowName: ''
- ClassName: '' WindowName: 'Windows Security Alert'
- ClassName: '' WindowName: 'BitDefender Firewall Alert'