Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MsSrv0] 'Logon' = 'MsSrvLogin'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MsSrv0] 'DLLName' = 'MsSrv0.DLL'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'Explorer.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MsSrv0] 'Startup' = 'MsSrvStartup'
- <SYSTEM32>\MsSrv0.dll
- <SYSTEM32>\MsSrv0.dl
- %TEMP%\mssrv.log
- %TEMP%\~dbI283p2.DLL
- %TEMP%\~6x3MerHv.DL
- %TEMP%\~6x3MerHv.DL в %TEMP%\~dbI283p2.DL
- ClassName: 'ExploreWClass' WindowName: ''
- ClassName: 'IME' WindowName: ''
- ClassName: 'Progman' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''