Техническая информация
- [HKLM\System\CurrentControlSet\Services\DWMRCS] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\DWMRCS] 'ImagePath' = '<SYSTEM32>\DWRCS.EXE -service'
- 'DWMRCS' <SYSTEM32>\DWRCS.EXE -service
- %TEMP%\dwd1282328\dwrcs.cfg
- %TEMP%\dwd1282328\dwrcsset.cfg
- %TEMP%\dwd1282328\dwrcs.exe
- %TEMP%\dwd1282328\dwrck.dll
- %TEMP%\dwd1282328\dwrcset.dll
- %TEMP%\dwd1282328\dwrcst.exe
- %TEMP%\dwd1282328\dwrcst.exe.manifest
- %TEMP%\dwd1282328\dwrcshell.dll
- %TEMP%\dwd1282328\dwrcsi.dll
- %TEMP%\dwd1282328\dwrcsp.cfg
- %TEMP%\dwd1282328\dwrcsu.cfg
- %WINDIR%\syswow64\dwrcs.exe
- %WINDIR%\syswow64\dwrck.dll
- %WINDIR%\syswow64\dwrcshell.dll
- %WINDIR%\syswow64\dwrcset.dll
- %WINDIR%\syswow64\dwrcst.exe
- %WINDIR%\syswow64\dwrcst.exe.manifest
- %WINDIR%\syswow64\dwrcs.ini
- %TEMP%\dwd1282328\dwrcsp.cfg
- %TEMP%\dwd1282328\dwrcsu.cfg
- %TEMP%\dwd1282328\dwrcsset.cfg
- %TEMP%\dwd1282328\dwrcs.cfg
- %TEMP%\dwd1282328\dwrcs.exe
- %TEMP%\dwd1282328\dwrck.dll
- %TEMP%\dwd1282328\dwrcset.dll
- %TEMP%\dwd1282328\dwrcshell.dll
- %TEMP%\dwd1282328\dwrcsi.dll
- %TEMP%\dwd1282328\dwrcst.exe
- %TEMP%\dwd1282328\dwrcst.exe.manifest
- 'localhost':6129
- ClassName: 'Progman' WindowName: ''
- '%WINDIR%\syswow64\dwrcs.exe' -service