Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\Windows_rejoice2007_45] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Windows_rejoice2007_45] 'ImagePath' = '%CommonProgramFiles%\Microsoft Shared\MSINFO\rejoice45.exe'
- 'Windows_rejoice2007_45' %CommonProgramFiles%\Microsoft Shared\MSINFO\rejoice45.exe
- %WINDIR%\syswow64\calc.exe
- iexplore.exe
- %CommonProgramFiles%\microsoft shared\msinfo\rejoice45.exe
- %WINDIR%\syswow64\_rejoice45.exe
- %CommonProgramFiles%\microsoft shared\msinfo\delet.bat
- %CommonProgramFiles%\microsoft shared\msinfo\rejoice45.exe
- %WINDIR%\syswow64\_rejoice45.exe
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- ClassName: 'Static' WindowName: ''
- '%CommonProgramFiles%\microsoft shared\msinfo\rejoice45.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%CommonProgramFiles%\Microsoft Shared\MSINFO\Delet.bat""' (со скрытым окном)
- '%WINDIR%\syswow64\calc.exe'
- '%ProgramFiles%\internet explorer\iexplore.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%CommonProgramFiles%\Microsoft Shared\MSINFO\Delet.bat""