Техническая информация
- [HKLM\System\CurrentControlSet\Services\qq] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\qq] 'ImagePath' = '<SYSTEM32>\svchost.exe -k imgsvc'
- 'qq' <SYSTEM32>\svchost.exe -k imgsvc
- ClassName: 'ollydbg', WindowName: ''
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- C:\444300.dll
- C:\nt_path.jpg
- C:\net-temp.ini
- %ProgramFiles(x86)%\bwxy\gwxyabcde.gif
- %ProgramFiles(x86)%\bwxy\gwxyabcde.gif
- C:\net-temp.ini
- C:\net-temp.ini
- ClassName: '' WindowName: '½ðɽ°²È«É³Ïä'
- ClassName: '' WindowName: 'Syser Debugger - Win32 User Mode Debugger'
- ClassName: '' WindowName: 'Syser : Active Hotkey [Ctrl+F12]'
- ClassName: 'WinDbgFrameClass' WindowName: ''
- ClassName: '' WindowName: 'Microsoft Spy++ - [´°¿Ú 1]'
- ClassName: 'SoftSnoopMainDialog' WindowName: ''
- ClassName: '18467-41' WindowName: ''
- ClassName: '4823-00000029' WindowName: ''