Техническая информация
- [HKLM\System\CurrentControlSet\Services\cpijwi] 'ImagePath' = '%WINDIR%\cpijwi.sys'
- 'cpijwi' %WINDIR%\cpijwi.sys
- %WINDIR%\cpijwi.sys
- %WINDIR%\temp\udd1f.tmp
- %WINDIR%\temp\udd925.tmp
- %WINDIR%\temp\udd1112.tmp
- %WINDIR%\temp\udd18e0.tmp
- %WINDIR%\temp\udd20bd.tmp
- %WINDIR%\temp\udd288b.tmp
- %WINDIR%\cpijwi.sys
- %WINDIR%\temp\udd1f.tmp
- %WINDIR%\temp\udd925.tmp
- %WINDIR%\temp\udd1112.tmp
- %WINDIR%\temp\udd18e0.tmp
- %WINDIR%\temp\udd20bd.tmp
- %WINDIR%\temp\udd288b.tmp
- %WINDIR%\cpijwi.sys
- '%WINDIR%\syswow64\cmd.exe' /C SC STOP cpijwi' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /C SC DELETE cpijwi' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /C SC STOP cpijwi
- '%WINDIR%\syswow64\sc.exe' STOP cpijwi
- '%WINDIR%\syswow64\cmd.exe' /C SC DELETE cpijwi
- '%WINDIR%\syswow64\sc.exe' DELETE cpijwi