Техническая информация
- [<HKLM>\SYSTEM\CurrentControlSet\services\NtHook] 'ImagePath' = '<DRIVERS>\NtHook.sys'
- [<HKLM>\SYSTEM\CurrentControlSet\services\NtHook] 'Start' = '00000001'
- [<HKLM>\SYSTEM\CurrentControlSet\services\NtHook] 'ImagePath' = 'System32\Drivers\NtHook.sys'
- [<HKLM>\SYSTEM\CurrentControlSet\services\Beep] 'Start' = '00000001'
- [<HKLM>\SYSTEM\CurrentControlSet\services\Beep] 'ImagePath' = 'System32\Drivers\Beep.sys'
- <DRIVERS>\beep.sys
- <DRIVERS>\nthook.sys
- <SYSTEM32>\safemon.dll
- <DRIVERS>\beep.sys.new
- <SYSTEM32>\dllcache\beep.sys.new