Техническая информация
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'WinTray' = '<SYSTEM32>\tarysrv.exe'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServices] 'WinTray' = '<SYSTEM32>\tarysrv.exe'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run] 'WinTray' = '<SYSTEM32>\tarysrv.exe'
- %WINDIR%\windebug.log
- %WINDIR%\syswow64\tarysrv.exe
- %WINDIR%\tmppp.exe
- DNS ASK pi###.#snelinimnado.com