Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\btzszewcmes] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\btzszewcmes] 'ImagePath' = '"%HOMEPATH%\trdyoyksycf.dat" service btzszewcmes'
- [<HKLM>\SYSTEM\ControlSet001\Services\btzszewcmes] 'ImagePath' = '"%HOMEPATH%\trdyoyksycf.dat" service btzszewcmes'
- [<HKLM>\SYSTEM\ControlSet001\Services\btzszewcmes] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet002\Services\btzszewcmes] 'ImagePath' = '"%HOMEPATH%\trdyoyksycf.dat" service btzszewcmes'
- [<HKLM>\SYSTEM\ControlSet002\Services\btzszewcmes] 'Start' = '00000002'
- 'btzszewcmes' "%HOMEPATH%\trdyoyksycf.dat" service btzszewcmes
- %HOMEPATH%\trdyoyksycf.dat
- %WINDIR%\temp\ ...
- %WINDIR%\temp\~dfafee1f0bad15a4dc.tmp
- %WINDIR%\temp\~df41680439d80ce698.tmp
- '%HOMEPATH%\trdyoyksycf.dat' service btzszewcmes
- '%WINDIR%\temp\ ...' daemon 648 2776100 41
- '%WINDIR%\temp\ ...' hatchery
- '%WINDIR%\temp\ ...' minion