Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\UnrealIRCd] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\UnrealIRCd] 'ImagePath' = 'c:\regged\csrss.exe'
- C:\regged\unrealircd.conf
- C:\regged\cloak.dll
- C:\regged\commands.dll
- C:\regged\csrss.exe
- C:\regged\install.bat
- C:\regged\msvcr70d.dll
- C:\regged\msvcrtd.dll
- C:\regged\tre.dll
- C:\regged\unreal.exe
- C:\regged\service.log
- C:\regged\tmp\65e36c42.commands.dll
- C:\regged\tmp\6e79ed54.cloak.dll
- C:\regged\tmp\6e79ed54.cloak.dll
- C:\regged\tmp\65e36c42.commands.dll
- ClassName: 'EDIT' WindowName: ''
- 'C:\regged\unreal.exe' install
- 'C:\regged\unreal.exe' config startup auto
- 'C:\regged\unreal.exe' config crashrestart 1
- 'C:\regged\unreal.exe' start
- 'C:\regged\csrss.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""C:\regged\install.bat" "
- '%WINDIR%\syswow64\cmd.exe' /C attrib +s +h c:\regged
- '%WINDIR%\syswow64\attrib.exe' +s +h c:\regged