Техническая информация
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\] 'NVIDIA driver monitor' = '%WINDIR%\nvsvc32.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\] 'NVIDIA driver monitor' = '%WINDIR%\nvsvc32.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run] 'NVIDIA driver monitor' = '%WINDIR%\nvsvc32.exe'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe' = '%WINDIR%\M...
- [<HKLM>\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe' = '%WINDIR%\n...
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram 1.exe 1 ENABLE
- %WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe
- %WINDIR%\nvsvc32.exb
- %WINDIR%\nvsvc32.exe
- %WINDIR%\nvsvc32.exe
- %WINDIR%\nvsvc32.exb
- '%WINDIR%\nvsvc32.exe'
- '%WINDIR%\nvsvc32.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram 1.exe 1 ENABLE' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe'