Техническая информация
- [HKLM\System\CurrentControlSet\Services\UpiKubar] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\UpiKubar] 'ImagePath' = '<SYSTEM32>\svchost.exe -k kuscer'
- [HKLM\SYSTEM\CurrentControlSet\Services\UpiKubar\Parameters] 'ServiceDll' = '%ProgramFiles(x86)%\GameBar\UpiKubar.dll'
- 'UpiKubar' <SYSTEM32>\svchost.exe -k kuscer
- %TEMP%\irsetup.exe
- %ProgramFiles(x86)%\gamebar\irunin.lng
- %ProgramFiles(x86)%\gamebar\irunin.dat
- %WINDIR%\iun6002.exe
- %ProgramFiles(x86)%\gamebar\fe067ae1a8.dat
- %ProgramFiles%\30b6e3d2a8.dat
- %ProgramFiles(x86)%\gamebar\upikubar.dll
- %ProgramFiles(x86)%\gamebar\config.ini
- %ProgramFiles(x86)%\gamebar\images\btn7.bmp
- %ProgramFiles(x86)%\gamebar\images\btn6.bmp
- %ProgramFiles(x86)%\gamebar\images\btn5.bmp
- %ProgramFiles(x86)%\gamebar\images\btn4.bmp
- %ProgramFiles(x86)%\gamebar\images\btn3.bmp
- %ProgramFiles(x86)%\gamebar\images\btn2.bmp
- %ProgramFiles(x86)%\gamebar\images\btn1.bmp
- %ProgramFiles(x86)%\gamebar\images\btn0.bmp
- %ProgramFiles(x86)%\gamebar\selcfg.ini
- %ProgramFiles(x86)%\gamebar\gamebar.dll
- %TEMP%\irsetup.ini
- %TEMP%\irimg3.bmp
- %TEMP%\irimg2.bmp
- %TEMP%\irimg1.bmp
- %TEMP%\suf6lng.4
- %TEMP%\irsetup.dat
- %ProgramFiles(x86)%\gamebar\irunin.bmp
- %ProgramFiles(x86)%\gamebar\irunin.ini
- DNS ASK co###.llads.cn
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_WINHELP' WindowName: ''
- '%TEMP%\irsetup.exe'
- '%WINDIR%\syswow64\svchost.exe' -k kuscer