Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Device Modem' = '<SYSTEM32>\spool\drivers\ModemSRV.exe'
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\List Picture.exe
- %ALLUSERSPROFILE%\Documents\My Music\Sample Music\List Sound.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\List Picture.exe
- <SYSTEM32>\spool\drivers\ModemSRV.exe