Техническая информация
- [<HKCU>\Software\Classes\discord-1025553627462508655\shell\open\command] '' = '<Полный путь к файлу>'
- [<HKLM>\System\CurrentControlSet\Services\PARAGON VIP_Hax] 'ImagePath' = '<Текущая директория>\PARAGON VIP_Hax.sys'
- 'PARAGON VIP_Hax' <Текущая директория>\PARAGON VIP_Hax.sys
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: 'RegmonClass', WindowName: ''
- <Текущая директория>\paragon vip_hax.sys
- %WINDIR%\temp\uddc88c.tmp
- %WINDIR%\temp\uddc88c.tmp
- ClassName: 'File Monitor - Sysinternals: www.sysinternals.com' WindowName: ''
- ClassName: 'Process Monitor - Sysinternals: www.sysinternals.com' WindowName: ''
- ClassName: 'Registry Monitor - Sysinternals: www.sysinternals.com' WindowName: ''
- ClassName: '18467-41' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c cls