Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices] 'Explore' = ''
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices] 'CPU Monitor' = ''
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'registry' = ''
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices] 'MSDN Key' = ''
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'MSDN Key' = ''
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Explore' = ''
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'CPU Monitor' = ''
- <SYSTEM32>\Process.exe -q regit.exe
- <SYSTEM32>\Process.exe -q reg.exe
- <SYSTEM32>\Process.exe -q change.exe
- <SYSTEM32>\runn.scr /S
- <SYSTEM32>\Process.exe -q broodrun.exe
- <SYSTEM32>\Process.exe -q wrag.exe
- %WINDIR%\regedit.exe /s dott.reg
- <SYSTEM32>\cmd.exe /c %TEMP%\~systmp.bat
- <SYSTEM32>\runn.scr
- %TEMP%\~systmp.bat
- <SYSTEM32>\dott.reg
- <SYSTEM32>\Process.exe
- <SYSTEM32>\rsvp.ini
- <SYSTEM32>\tcpmon.ini
- <SYSTEM32>\pschdprf.ini
- <SYSTEM32>\rasctrs.ini
- <SYSTEM32>\tslabels.ini
- <SYSTEM32>\ieuinit.inf
- <SYSTEM32>\mmdriver.inf
- <SYSTEM32>\$winnt$.inf
- <SYSTEM32>\homepage.inf
- <SYSTEM32>\prodspec.ini
- <SYSTEM32>\esentprf.ini
- <SYSTEM32>\mqperf.ini
- <SYSTEM32>\runn.scr
- <SYSTEM32>\desktop.ini
- <SYSTEM32>\msdtcprf.ini
- <SYSTEM32>\PerfStringBackup.INI
- <SYSTEM32>\perfwci.ini
- <SYSTEM32>\perfci.ini
- <SYSTEM32>\perffilt.ini
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''