Техническая информация
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'SessMgr' = '<DRIVERS>\sessmgr.exe /waitservice'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'Logman' = '%WINDIR%\System\logman.exe /waitservice'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'ClipSrv' = '%WINDIR%\clipsrv.exe /waitservice'
- [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%WINDIR%\sessmgr.exe'
- %WINDIR%\syswow64\drivers\sessmgr.exe
- %WINDIR%\system\logman.exe
- %WINDIR%\clipsrv.exe
- %WINDIR%\sessmgr.exe
- DNS ASK ka##rap.com
- '%WINDIR%\sessmgr.exe' /waitservice