Техническая информация
- [HKLM\System\CurrentControlSet\Services\windows ºËÐÄ×é¼þ·þÎñÏî] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\windows ºËÐÄ×é¼þ·þÎñÏî] 'ImagePath' = '%WINDIR%\exploret.exe'
- 'windows ºËÐÄ×é¼þ·þÎñÏî' %WINDIR%\exploret.exe
- %WINDIR%\syswow64\svchost.exe
- %TEMP%\ixp000.tmp\1.exe
- %WINDIR%\exploret.exe
- %WINDIR%\exploret.exe
- %TEMP%\ixp000.tmp\1.exe
- '%TEMP%\ixp000.tmp\1.exe'
- '%WINDIR%\exploret.exe'
- '%WINDIR%\syswow64\svchost.exe'
- '%TEMP%\ixp000.tmp\1.exe' (со скрытым окном)