Техническая информация
- [HKLM\System\CurrentControlSet\Services\TRDR] 'ImagePath' = 'C:\TRDR.sys'
- 'TRDR' C:\TRDR.sys
- C:\trdr.sys
- %WINDIR%\temp\uddd1ee.tmp
- %WINDIR%\temp\uddd9cc.tmp
- %WINDIR%\temp\udde199.tmp
- %WINDIR%\temp\udde967.tmp
- %WINDIR%\temp\uddf135.tmp
- %WINDIR%\temp\uddf903.tmp
- C:\trdr.sys
- %WINDIR%\temp\uddd1ee.tmp
- %WINDIR%\temp\uddd9cc.tmp
- %WINDIR%\temp\udde199.tmp
- %WINDIR%\temp\udde967.tmp
- %WINDIR%\temp\uddf135.tmp
- %WINDIR%\temp\uddf903.tmp
- C:\trdr.sys
- '%WINDIR%\syswow64\cmd.exe' /C SC STOP TRDR' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /C SC DELETE TRDR' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /C SC STOP TRDR
- '%WINDIR%\syswow64\sc.exe' STOP TRDR
- '%WINDIR%\syswow64\cmd.exe' /C SC DELETE TRDR
- '%WINDIR%\syswow64\sc.exe' DELETE TRDR