Техническая информация
- [<HKLM>\SOFTWARE\Classes\txtfile\shell\open\command] '' = '<SYSTEM32>\lsasa.exe "%1"'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'Explorer.exe a1g.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ctfnom.exe' = '%WINDIR%\SVOHOST.exe'
- %WINDIR%\SVOHOST.exe
- <SYSTEM32>\lsasa.exe
- <SYSTEM32>\a1g.exe
- %WINDIR%\SVOHOST.exe
- ClassName: 'tucpanel' WindowName: ''
- ClassName: 'tucbutton' WindowName: '????(&S)'
- ClassName: 'tpanel' WindowName: ''
- ClassName: 'tpanel' WindowName: 'panel1'
- ClassName: 'tpanel' WindowName: 'mainpanel'
- ClassName: 'tpanel' WindowName: 'editpanel'
- ClassName: 'richedit20w' WindowName: ''
- ClassName: 'AfxOleControl42' WindowName: ''
- ClassName: 'DirectUIHWND' WindowName: ''
- ClassName: 'trichedit2' WindowName: ''
- ClassName: 'cuteedit' WindowName: ''
- ClassName: 'Button' WindowName: '??????(&S)'
- ClassName: 'ThunderRT6FormDC' WindowName: 'Windows ??????????'
- ClassName: '#32770' WindowName: '??????????'
- ClassName: '' WindowName: ''
- ClassName: 'ddqxyz' WindowName: 'joyiex'
- ClassName: 'soft' WindowName: 'win9x'
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'RICHEDIT' WindowName: ''
- ClassName: 'Button' WindowName: '????(&S)'
- ClassName: 'AfxWnd42' WindowName: ''
- ClassName: '#32770' WindowName: ''
- ClassName: 'RichEdit20A' WindowName: ''