Техническая информация
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'SystemMonitoring' = '<SYSTEM32>\1sass.exe'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'SystemServices' = '<SYSTEM32>\SERVlCES.exe'
- скрытых файлов
- расширений файлов
- Компонент восстановления системы (SR)
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFolderOptions' = '00000001'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFolderOptions' = '00000001'
- %WINDIR%\syswow64\1sass.exe
- %WINDIR%\syswow64\servlces.exe
- %WINDIR%\syswow64\about_mp.html
- C:\meutya_hafid.exe
- C:\zelda_savitri.exe
- C:\wianda_pusponegoro.exe
- C:\gadiza_fauzi.exe
- C:\frida_lidwina.exe
- C:\najwa_sihab.exe
- C:\kania_sutisnawinata.exe
- C:\prita_laura.exe
- %WINDIR%\syswow64\1sass.exe
- %WINDIR%\syswow64\servlces.exe
- %WINDIR%\syswow64\about_mp.html
- ClassName: 'WorkerW' WindowName: ''
- ClassName: 'ReBarWindow32' WindowName: ''
- ClassName: 'ComboBoxEx32' WindowName: ''
- ClassName: 'ComboBox' WindowName: ''
- ClassName: 'Edit' WindowName: ''
- ClassName: 'ExploreWClass' WindowName: ''