Техническая информация
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'msorcvp' = '%WINDIR%\msorcvp.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'msorcvp' = '%WINDIR%\msorcvp.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServices] 'msorcvp' = '%WINDIR%\msorcvp.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'lsassv' = '%WINDIR%\lsassv.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'msrpc' = '%WINDIR%\msrpc.exe'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\msorcvp] 'ImagePath' = '%WINDIR%\msorcvp.exe'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\msorcvp] 'Start' = '00000002'
- 'msorcvp' %WINDIR%\msorcvp.exe
- [<HKLM>\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<Полный путь к файлу>' = '<Полный путь к файлу>:*:Enabled:System U...
- ClassName: '', WindowName: 'Windows File Protection'
- %WINDIR%\msorcvp.exe
- %WINDIR%\mui\rctfd.sys
- %WINDIR%\lsassv.exe
- %WINDIR%\msrpc.exe
- %WINDIR%\calc.exe
- %WINDIR%\regedit2.exe
- C:\documents and settings\all users\start menu\programs\startup\adobegammaloader.scr
- ClassName: 'Button' WindowName: ''
- ClassName: '' WindowName: 'Çà ùèòà ôà éëîâ Windows'