Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%WINDIR%\igfxext.exe' = '%WINDIR%\igfxext.exe:*:Enabled:igfxext.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\sessmgr.exe' = '<SYSTEM32>\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019'
- <SYSTEM32>\attrib.exe +h %WINDIR%\ver.ini
- %WINDIR%\regedit.exe /s %WINDIR%\winxp.reg
- <SYSTEM32>\tskill.exe ravmon
- <SYSTEM32>\regsvr32.exe /s %WINDIR%\REGTOOL5.DLL
- <SYSTEM32>\cmd.exe /c ""%WINDIR%\winupdate.bat" "
- %WINDIR%\winxp.reg
- %WINDIR%\xaclgn.cfg
- %WINDIR%\scrrun.dll
- %WINDIR%\system.old
- %WINDIR%\ver.ini
- %WINDIR%\winupdate.bat
- %WINDIR%\upload.dll
- %WINDIR%\APPRULE.FWR
- %WINDIR%\AUTOFIX.EXE
- %WINDIR%\AppRule.dat
- %WINDIR%\cabarc.exe
- %WINDIR%\REGTOOL5.DLL
- %WINDIR%\MSSTDFMT.DLL
- %WINDIR%\FWUserAuditRul.xml
- %WINDIR%\ver.ini
- %TEMP%\~DFC8A7.tmp
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''