Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'svchost' = '<Полный путь к файлу>'
- [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] 'svchost' = '<Полный путь к файлу>'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'svchost' = '<Полный путь к файлу>'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsService' = '<SYSTEM32>\svchost.exe'
- [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsService' = '<SYSTEM32>\svchost.exe'
- [HKLM\SYSTEM\CurrentControlSet\Control\Session Manager] 'BootExecute' = '<SYSTEM32>\svchost.exe'
- %APPDATA%\microsoft\windows\start menu\programs\startup\svchost.exe
- <SYSTEM32>\tasks\windowsservice
- <SYSTEM32>\tasks\windowsservicetask
- <SYSTEM32>\tasks\windowsservicedaily
- [HKLM\SYSTEM\CurrentControlSet\Services\WindowsService] 'Start' = '00000002'
- 'WindowsService' <SYSTEM32>\svchost.exe
- <Имя диска съемного носителя>:\systemservice.exe
- <Имя диска съемного носителя>:\autorun.inf
- <SYSTEM32>\agentactivationruntimestarter.exe.inf
- <SYSTEM32>\agentservice.exe.inf
- <SYSTEM32>\aitstatic.exe.inf
- <SYSTEM32>\alg.exe.inf
- <SYSTEM32>\apphostregistrationverifier.exe.inf
- <SYSTEM32>\appidcertstorecheck.exe.inf
- <SYSTEM32>\appidpolicyconverter.exe.inf
- <SYSTEM32>\appidtel.exe.inf
- <SYSTEM32>\applicationframehost.exe.inf
- <SYSTEM32>\applysettingstemplatecatalog.exe.inf
- <SYSTEM32>\applytrustoffline.exe.inf
- <SYSTEM32>\approvechildrequest.exe.inf
- <SYSTEM32>\appvclient.exe.inf
- <SYSTEM32>\appvdllsurrogate.exe.inf
- <SYSTEM32>\appvnice.exe.inf
- <SYSTEM32>\appvshnotify.exe.inf
- <SYSTEM32>\arp.exe.inf
- <SYSTEM32>\assignedaccessguard.exe.inf
- <SYSTEM32>\at.exe.inf
- <SYSTEM32>\atbroker.exe.inf
- <SYSTEM32>\attrib.exe.inf
- <SYSTEM32>\audiodg.exe.inf
- <SYSTEM32>\auditpol.exe.inf
- <SYSTEM32>\authhost.exe.inf
- <SYSTEM32>\autochk.exe.inf
- <SYSTEM32>\autoconv.exe.inf
- <SYSTEM32>\autofmt.exe.inf
- <SYSTEM32>\axinstui.exe.inf
- <SYSTEM32>\baaupdate.exe.inf
- <SYSTEM32>\backgroundtaskhost.exe.inf
- <SYSTEM32>\backgroundtransferhost.exe.inf
- <SYSTEM32>\bcdboot.exe.inf
- <SYSTEM32>\bcdedit.exe.inf
- <SYSTEM32>\bdechangepin.exe.inf
- <SYSTEM32>\bdehdcfg.exe.inf
- <SYSTEM32>\bdeuisrv.exe.inf
- <SYSTEM32>\bdeunlock.exe.inf
- <SYSTEM32>\bioiso.exe.inf
- <SYSTEM32>\bitlockerdeviceencryption.exe.inf
- <SYSTEM32>\bitlockerwizard.exe.inf
- <SYSTEM32>\bitlockerwizardelev.exe.inf
- <SYSTEM32>\bitsadmin.exe.inf
- <SYSTEM32>\bootcfg.exe.inf
- <SYSTEM32>\bootim.exe.inf
- <SYSTEM32>\bootsect.exe.inf
- <SYSTEM32>\bridgeunattend.exe.inf
- <SYSTEM32>\browserexport.exe.inf
- <SYSTEM32>\browser_broker.exe.inf
- <SYSTEM32>\bthudtask.exe.inf
- <SYSTEM32>\bytecodegenerator.exe.inf
- <SYSTEM32>\cacls.exe.inf
- <SYSTEM32>\calc.exe.inf
- <SYSTEM32>\camerasettingsuihost.exe.inf
- <SYSTEM32>\castsrv.exe.inf
- <SYSTEM32>\certenrollctrl.exe.inf
- <SYSTEM32>\certreq.exe.inf
- <SYSTEM32>\certutil.exe.inf
- <SYSTEM32>\change.exe.inf
- <SYSTEM32>\changepk.exe.inf
- <SYSTEM32>\charmap.exe.inf
- <SYSTEM32>\checknetisolation.exe.inf
- <SYSTEM32>\chglogon.exe.inf
- <SYSTEM32>\chgport.exe.inf
- <SYSTEM32>\chgusr.exe.inf
- <SYSTEM32>\chkdsk.exe.inf
- <SYSTEM32>\chkntfs.exe.inf
- <SYSTEM32>\choice.exe.inf
- <SYSTEM32>\cidiag.exe.inf
- <SYSTEM32>\cipher.exe.inf
- <SYSTEM32>\cleanmgr.exe.inf
- <SYSTEM32>\cliconfg.exe.inf
- <SYSTEM32>\clip.exe.inf
- <SYSTEM32>\cliprenew.exe.inf
- <SYSTEM32>\clipup.exe.inf
- <SYSTEM32>\cloudexperiencehostbroker.exe.inf
- <SYSTEM32>\cloudnotifications.exe.inf
- <SYSTEM32>\cmd.exe.inf
- <SYSTEM32>\cmdkey.exe.inf
- <SYSTEM32>\cmdl32.exe.inf
- <SYSTEM32>\cmmon32.exe.inf
- <SYSTEM32>\cmstp.exe.inf
- <SYSTEM32>\cofire.exe.inf
- <SYSTEM32>\colorcpl.exe.inf
- <SYSTEM32>\comp.exe.inf
- <SYSTEM32>\compact.exe.inf
- <SYSTEM32>\compattelrunner.exe.inf
- <SYSTEM32>\compmgmtlauncher.exe.inf
- <SYSTEM32>\comppkgsrv.exe.inf
- <SYSTEM32>\computerdefaults.exe.inf
- <SYSTEM32>\conhost.exe.inf
- <SYSTEM32>\consent.exe.inf
- <SYSTEM32>\control.exe.inf
- <SYSTEM32>\convert.exe.inf
- <SYSTEM32>\convertvhd.exe.inf
- <SYSTEM32>\coredpussvr.exe.inf
- <SYSTEM32>\credentialenrollmentmanager.exe.inf
- <SYSTEM32>\credentialuibroker.exe.inf
- <SYSTEM32>\credwiz.exe.inf
- <SYSTEM32>\cscript.exe.inf
- <SYSTEM32>\ctfmon.exe.inf
- <SYSTEM32>\cttune.exe.inf
- <SYSTEM32>\cttunesvr.exe.inf
- <SYSTEM32>\curl.exe.inf
- <SYSTEM32>\custominstallexec.exe.inf
- <SYSTEM32>\customshellhost.exe.inf
- <SYSTEM32>\dashost.exe.inf
- <SYSTEM32>\dataexchangehost.exe.inf
- <SYSTEM32>\datastorecachedumptool.exe.inf
- <SYSTEM32>\datausagelivetiletask.exe.inf
- <SYSTEM32>\dccw.exe.inf
- <SYSTEM32>\dcomcnfg.exe.inf
- <SYSTEM32>\ddodiag.exe.inf
- <SYSTEM32>\defrag.exe.inf
- <SYSTEM32>\deploymentcsphelper.exe.inf
- <SYSTEM32>\desktopimgdownldr.exe.inf
- <SYSTEM32>\devicecensus.exe.inf
- <SYSTEM32>\devicecredentialdeployment.exe.inf
- <SYSTEM32>\deviceeject.exe.inf
- <SYSTEM32>\deviceenroller.exe.inf
- <SYSTEM32>\devicepairingwizard.exe.inf
- <SYSTEM32>\deviceproperties.exe.inf
- <SYSTEM32>\dfdwiz.exe.inf
- <SYSTEM32>\dfrgui.exe.inf
- <SYSTEM32>\dialer.exe.inf
- <SYSTEM32>\directxdatabaseupdater.exe.inf
- <SYSTEM32>\diskpart.exe.inf
- <SYSTEM32>\diskperf.exe.inf
- <SYSTEM32>\diskraid.exe.inf
- <SYSTEM32>\disksnapshot.exe.inf
- <SYSTEM32>\dism.exe.inf
- <SYSTEM32>\dispdiag.exe.inf
- <SYSTEM32>\displayswitch.exe.inf
- <SYSTEM32>\djoin.exe.inf
- <SYSTEM32>\dllhost.exe.inf
- <SYSTEM32>\dllhst3g.exe.inf
- <SYSTEM32>\dmcertinst.exe.inf
- <SYSTEM32>\dmcfghost.exe.inf
- <SYSTEM32>\dmclient.exe.inf
- <SYSTEM32>\dmnotificationbroker.exe.inf
- <SYSTEM32>\dmomacpmo.exe.inf
- <SYSTEM32>\dnscacheugc.exe.inf
- <SYSTEM32>\doskey.exe.inf
- <SYSTEM32>\dpapimig.exe.inf
- <SYSTEM32>\dpiscaling.exe.inf
- <SYSTEM32>\dpnsvr.exe.inf
- <SYSTEM32>\driverquery.exe.inf
- <SYSTEM32>\drvinst.exe.inf
- <SYSTEM32>\dsmusertask.exe.inf
- <SYSTEM32>\dsregcmd.exe.inf
- <SYSTEM32>\dstokenclean.exe.inf
- <SYSTEM32>\dtuhandler.exe.inf
- <SYSTEM32>\dusmtask.exe.inf
- <SYSTEM32>\dvdplay.exe.inf
- <SYSTEM32>\dwm.exe.inf
- <SYSTEM32>\dwwin.exe.inf
- <SYSTEM32>\dxdiag.exe.inf
- <SYSTEM32>\dxgiadaptercache.exe.inf
- <SYSTEM32>\dxpserver.exe.inf
- <SYSTEM32>\eap3host.exe.inf
- <SYSTEM32>\easeofaccessdialog.exe.inf
- <SYSTEM32>\easinvoker.exe.inf
- <SYSTEM32>\easpolicymanagerbrokerhost.exe.inf
- <SYSTEM32>\edpcleanup.exe.inf
- <SYSTEM32>\edpnotify.exe.inf
- <SYSTEM32>\eduprintprov.exe.inf
- <SYSTEM32>\efsui.exe.inf
- <SYSTEM32>\ehstorauthn.exe.inf
- <SYSTEM32>\eoaexperiences.exe.inf
- <SYSTEM32>\esentutl.exe.inf
- <SYSTEM32>\eudcedit.exe.inf
- <SYSTEM32>\eventcreate.exe.inf
- <SYSTEM32>\eventvwr.exe.inf
- <SYSTEM32>\expand.exe.inf
- <SYSTEM32>\extrac32.exe.inf
- <SYSTEM32>\fc.exe.inf
- <SYSTEM32>\fhmanagew.exe.inf
- <SYSTEM32>\filehistory.exe.inf
- <SYSTEM32>\find.exe.inf
- <SYSTEM32>\findstr.exe.inf
- <SYSTEM32>\finger.exe.inf
- <SYSTEM32>\fixmapi.exe.inf
- <SYSTEM32>\fltmc.exe.inf
- <SYSTEM32>\fodhelper.exe.inf
- <SYSTEM32>\fondue.exe.inf
- <SYSTEM32>\fontdrvhost.exe.inf
- <SYSTEM32>\fontview.exe.inf
- <SYSTEM32>\forfiles.exe.inf
- <SYSTEM32>\fsavailux.exe.inf
- <SYSTEM32>\fsiso.exe.inf
- <SYSTEM32>\fsquirt.exe.inf
- <SYSTEM32>\fsutil.exe.inf
- <SYSTEM32>\ftp.exe.inf
- <SYSTEM32>\fvenotify.exe.inf
- <SYSTEM32>\fveprompt.exe.inf
- <SYSTEM32>\fxscover.exe.inf
- <SYSTEM32>\fxssvc.exe.inf
- <SYSTEM32>\fxsunatd.exe.inf
- <SYSTEM32>\gamebarpresencewriter.exe.inf
- <SYSTEM32>\gamepanel.exe.inf
- <SYSTEM32>\genvalobj.exe.inf
- <SYSTEM32>\getmac.exe.inf
- <SYSTEM32>\gpresult.exe.inf
- <SYSTEM32>\gpscript.exe.inf
- <SYSTEM32>\gpupdate.exe.inf
- <SYSTEM32>\grpconv.exe.inf
- <SYSTEM32>\hdwwiz.exe.inf
- <SYSTEM32>\help.exe.inf
- <SYSTEM32>\hostname.exe.inf
- <SYSTEM32>\hvax64.exe.inf
- <SYSTEM32>\hvix64.exe.inf
- <SYSTEM32>\hvsievaluator.exe.inf
- <SYSTEM32>\icacls.exe.inf
- <SYSTEM32>\icsentitlementhost.exe.inf
- <SYSTEM32>\icsunattend.exe.inf
- <SYSTEM32>\ie4uinit.exe.inf
- <SYSTEM32>\ie4ushowie.exe.inf
- <SYSTEM32>\iesettingsync.exe.inf
- <SYSTEM32>\ieunatt.exe.inf
- <SYSTEM32>\iexpress.exe.inf
- <SYSTEM32>\immersivetpmvscmgrsvr.exe.inf
- <SYSTEM32>\infdefaultinstall.exe.inf
- <SYSTEM32>\inputswitchtoasthandler.exe.inf
- <SYSTEM32>\iotstartup.exe.inf
- <SYSTEM32>\ipconfig.exe.inf
- <SYSTEM32>\iscsicli.exe.inf
- <SYSTEM32>\iscsicpl.exe.inf
- <SYSTEM32>\isoburn.exe.inf
- <SYSTEM32>\klist.exe.inf
- <SYSTEM32>\ksetup.exe.inf
- <SYSTEM32>\ktmutil.exe.inf
- <SYSTEM32>\label.exe.inf
- <SYSTEM32>\languagecomponentsinstallercomhandler.exe.inf
- <SYSTEM32>\launchtm.exe.inf
- <SYSTEM32>\launchwinapp.exe.inf
- <SYSTEM32>\legacynetuxhost.exe.inf
- <SYSTEM32>\licensemanagershellext.exe.inf
- <SYSTEM32>\licensingdiag.exe.inf
- <SYSTEM32>\licensingui.exe.inf
- <SYSTEM32>\locationnotificationwindows.exe.inf
- <SYSTEM32>\locator.exe.inf
- <SYSTEM32>\lockapphost.exe.inf
- <SYSTEM32>\lockscreencontentserver.exe.inf
- <SYSTEM32>\lodctr.exe.inf
- <SYSTEM32>\logagent.exe.inf
- <SYSTEM32>\logman.exe.inf
- <SYSTEM32>\logoff.exe.inf
- <SYSTEM32>\logonui.exe.inf
- <SYSTEM32>\lpkinstall.exe.inf
- <SYSTEM32>\lpksetup.exe.inf
- <SYSTEM32>\lpremove.exe.inf
- <SYSTEM32>\lsaiso.exe.inf
- <SYSTEM32>\lsass.exe.inf
- <SYSTEM32>\magnify.exe.inf
- <SYSTEM32>\makecab.exe.inf
- <SYSTEM32>\manage-bde.exe.inf
- <SYSTEM32>\mavinject.exe.inf
- <SYSTEM32>\mbaeparsertask.exe.inf
- <SYSTEM32>\mblctr.exe.inf
- <SYSTEM32>\mbr2gpt.exe.inf
- <SYSTEM32>\mcbuilder.exe.inf
- <SYSTEM32>\mdeserver.exe.inf
- <SYSTEM32>\mdmagent.exe.inf
- <SYSTEM32>\mdmappinstaller.exe.inf
- <SYSTEM32>\mdmdiagnosticstool.exe.inf
- <SYSTEM32>\mdres.exe.inf
- <SYSTEM32>\mdsched.exe.inf
- <SYSTEM32>\mfpmp.exe.inf
- <SYSTEM32>\microsoft.uev.cscunpintool.exe.inf
- <SYSTEM32>\microsoft.uev.synccontroller.exe.inf
- <SYSTEM32>\microsoftedgebchost.exe.inf
- <SYSTEM32>\microsoftedgecp.exe.inf
- <SYSTEM32>\microsoftedgedevtools.exe.inf
- <SYSTEM32>\microsoftedgesh.exe.inf
- <SYSTEM32>\mmc.exe.inf
- <SYSTEM32>\mmgaserver.exe.inf
- <SYSTEM32>\mobsync.exe.inf
- <SYSTEM32>\mountvol.exe.inf
- <SYSTEM32>\mousocoreworker.exe.inf
- <SYSTEM32>\mpnotify.exe.inf
- <SYSTEM32>\mrinfo.exe.inf
- <SYSTEM32>\mschedexe.exe.inf
- <SYSTEM32>\msconfig.exe.inf
- <SYSTEM32>\msdt.exe.inf
- <SYSTEM32>\msdtc.exe.inf
- <SYSTEM32>\msfeedssync.exe.inf
- <SYSTEM32>\msg.exe.inf
- <SYSTEM32>\mshta.exe.inf
- <SYSTEM32>\msiexec.exe.inf
- <SYSTEM32>\msinfo32.exe.inf
- <SYSTEM32>\mspaint.exe.inf
- <SYSTEM32>\msra.exe.inf
- <SYSTEM32>\msspellcheckinghost.exe.inf
- <SYSTEM32>\mstsc.exe.inf
- <SYSTEM32>\mtstocom.exe.inf
- <SYSTEM32>\muiunattend.exe.inf
- <SYSTEM32>\multidigimon.exe.inf
- <SYSTEM32>\musnotification.exe.inf
- <SYSTEM32>\musnotificationux.exe.inf
- <SYSTEM32>\musnotifyicon.exe.inf
- <SYSTEM32>\narrator.exe.inf
- <SYSTEM32>\nbtstat.exe.inf
- <SYSTEM32>\ndadmin.exe.inf
- <SYSTEM32>\ndkping.exe.inf
- <SYSTEM32>\net.exe.inf
- <SYSTEM32>\net1.exe.inf
- <SYSTEM32>\netbtugc.exe.inf
- <SYSTEM32>\netcfg.exe.inf
- <SYSTEM32>\netcfgnotifyobjecthost.exe.inf
- <SYSTEM32>\netevtfwdr.exe.inf
- <SYSTEM32>\nethost.exe.inf
- <SYSTEM32>\netiougc.exe.inf
- <SYSTEM32>\netplwiz.exe.inf
- <SYSTEM32>\netsh.exe.inf
- <SYSTEM32>\netstat.exe.inf
- <SYSTEM32>\newdev.exe.inf
- <SYSTEM32>\ngciso.exe.inf
- <SYSTEM32>\nltest.exe.inf
- <SYSTEM32>\notepad.exe.inf
- <SYSTEM32>\nslookup.exe.inf
- <SYSTEM32>\ntoskrnl.exe.inf
- <SYSTEM32>\ntprint.exe.inf
- <SYSTEM32>\odbcad32.exe.inf
- <SYSTEM32>\odbcconf.exe.inf
- <SYSTEM32>\ofdeploy.exe.inf
- <SYSTEM32>\omadmclient.exe.inf
- <SYSTEM32>\omadmprc.exe.inf
- <SYSTEM32>\openfiles.exe.inf
- <SYSTEM32>\openwith.exe.inf
- <SYSTEM32>\optionalfeatures.exe.inf
- <SYSTEM32>\osk.exe.inf
- <SYSTEM32>\pacjsworker.exe.inf
- <SYSTEM32>\packagedcwalauncher.exe.inf
- <SYSTEM32>\packageinspector.exe.inf
- <SYSTEM32>\passwordonwakesettingflyout.exe.inf
- <SYSTEM32>\pathping.exe.inf
- <SYSTEM32>\pcalua.exe.inf
- <SYSTEM32>\pcaui.exe.inf
- <SYSTEM32>\pcwrun.exe.inf
- <SYSTEM32>\perfmon.exe.inf
- <SYSTEM32>\phoneactivate.exe.inf
- <SYSTEM32>\pickerhost.exe.inf
- <SYSTEM32>\pinenrollmentbroker.exe.inf
- <SYSTEM32>\ping.exe.inf
- <SYSTEM32>\pkgmgr.exe.inf
- <SYSTEM32>\pktmon.exe.inf
- <SYSTEM32>\plasrv.exe.inf
- <SYSTEM32>\pnpunattend.exe.inf
- <SYSTEM32>\pnputil.exe.inf
- <SYSTEM32>\poqexec.exe.inf
- <SYSTEM32>\pospaymentsworker.exe.inf
- <SYSTEM32>\powercfg.exe.inf
- <SYSTEM32>\presentationhost.exe.inf
- <SYSTEM32>\presentationsettings.exe.inf
- <SYSTEM32>\prevhost.exe.inf
- <SYSTEM32>\print.exe.inf
- <SYSTEM32>\printbrmui.exe.inf
- <SYSTEM32>\printfilterpipelinesvc.exe.inf
- <SYSTEM32>\printisolationhost.exe.inf
- <SYSTEM32>\printui.exe.inf
- <SYSTEM32>\proquota.exe.inf
- <SYSTEM32>\provlaunch.exe.inf
- <SYSTEM32>\provtool.exe.inf
- <SYSTEM32>\proximityuxhost.exe.inf
- <SYSTEM32>\prproc.exe.inf
- <SYSTEM32>\psr.exe.inf
- <SYSTEM32>\pwlauncher.exe.inf
- <SYSTEM32>\qappsrv.exe.inf
- <SYSTEM32>\qprocess.exe.inf
- <SYSTEM32>\query.exe.inf
- <SYSTEM32>\quickassist.exe.inf
- <SYSTEM32>\quser.exe.inf
- <SYSTEM32>\qwinsta.exe.inf
- <SYSTEM32>\rasautou.exe.inf
- <SYSTEM32>\rasdial.exe.inf
- <SYSTEM32>\raserver.exe.inf
- <SYSTEM32>\rasphone.exe.inf
- <SYSTEM32>\rdpclip.exe.inf
- <SYSTEM32>\rdpinit.exe.inf
- <SYSTEM32>\rdpinput.exe.inf
- <SYSTEM32>\rdpsa.exe.inf
- <SYSTEM32>\rdpsaproxy.exe.inf
- <SYSTEM32>\rdpsauachelper.exe.inf
- <SYSTEM32>\rdpshell.exe.inf
- <SYSTEM32>\rdpsign.exe.inf
- <SYSTEM32>\rdrleakdiag.exe.inf
- <SYSTEM32>\reagentc.exe.inf
- <SYSTEM32>\recdisc.exe.inf
- <SYSTEM32>\recover.exe.inf
- <SYSTEM32>\recoverydrive.exe.inf
- <SYSTEM32>\refsutil.exe.inf
- <SYSTEM32>\reg.exe.inf
- <SYSTEM32>\regedt32.exe.inf
- <SYSTEM32>\regini.exe.inf
- <SYSTEM32>\register-cimprovider.exe.inf
- <SYSTEM32>\regsvr32.exe.inf
- <SYSTEM32>\rekeywiz.exe.inf
- <SYSTEM32>\relog.exe.inf
- <SYSTEM32>\relpost.exe.inf
- <SYSTEM32>\remoteapplifetimemanager.exe.inf
- <SYSTEM32>\remoteposworker.exe.inf
- <SYSTEM32>\repair-bde.exe.inf
- <SYSTEM32>\replace.exe.inf
- <SYSTEM32>\reset.exe.inf
- <SYSTEM32>\resetengine.exe.inf
- <SYSTEM32>\resmon.exe.inf
- <SYSTEM32>\rmactivate.exe.inf
- <SYSTEM32>\rmactivate_isv.exe.inf
- <SYSTEM32>\rmactivate_ssp.exe.inf
- <SYSTEM32>\rmactivate_ssp_isv.exe.inf
- <SYSTEM32>\rmclient.exe.inf
- <SYSTEM32>\rmttpmvscmgrsvr.exe.inf
- <SYSTEM32>\robocopy.exe.inf
- <SYSTEM32>\route.exe.inf
- <SYSTEM32>\rpcping.exe.inf
- <SYSTEM32>\rrinstaller.exe.inf
- <SYSTEM32>\rstrui.exe.inf
- <SYSTEM32>\runas.exe.inf
- <SYSTEM32>\rundll32.exe.inf
- <SYSTEM32>\runexehelper.exe.inf
- <SYSTEM32>\runlegacycplelevated.exe.inf
- <SYSTEM32>\runonce.exe.inf
- <SYSTEM32>\runtimebroker.exe.inf
- <SYSTEM32>\rwinsta.exe.inf
- <SYSTEM32>\sc.exe.inf
- <SYSTEM32>\schtasks.exe.inf
- <SYSTEM32>\scriptrunner.exe.inf
- <SYSTEM32>\sdbinst.exe.inf
- <SYSTEM32>\sdchange.exe.inf
- <SYSTEM32>\sdclt.exe.inf
- <SYSTEM32>\sdiagnhost.exe.inf
- <SYSTEM32>\searchfilterhost.exe.inf
- <SYSTEM32>\searchindexer.exe.inf
- <SYSTEM32>\searchprotocolhost.exe.inf
- <SYSTEM32>\secedit.exe.inf
- <SYSTEM32>\secinit.exe.inf
- <SYSTEM32>\securekernel.exe.inf
- <SYSTEM32>\securityhealthhost.exe.inf
- <SYSTEM32>\securityhealthservice.exe.inf
- <SYSTEM32>\securityhealthsystray.exe.inf
- <SYSTEM32>\sensordataservice.exe.inf
- <SYSTEM32>\services.exe.inf
- <SYSTEM32>\sessionmsg.exe.inf
- <SYSTEM32>\sethc.exe.inf
- <SYSTEM32>\setspn.exe.inf
- <SYSTEM32>\settingsynchost.exe.inf
- <SYSTEM32>\setupcl.exe.inf
- <SYSTEM32>\setupugc.exe.inf
- <SYSTEM32>\setx.exe.inf
- <SYSTEM32>\sfc.exe.inf
- <SYSTEM32>\sgrmbroker.exe.inf
- <SYSTEM32>\sgrmlpac.exe.inf
- <SYSTEM32>\shrpubw.exe.inf
- <SYSTEM32>\shutdown.exe.inf
- <SYSTEM32>\sigverif.exe.inf
- <SYSTEM32>\sihclient.exe.inf
- <SYSTEM32>\sihost.exe.inf
- <SYSTEM32>\slidetoshutdown.exe.inf
- <SYSTEM32>\slui.exe.inf
- <SYSTEM32>\sndvol.exe.inf
- <SYSTEM32>\snippingtool.exe.inf
- <SYSTEM32>\snmptrap.exe.inf
- <SYSTEM32>\sort.exe.inf
- <SYSTEM32>\spaceagent.exe.inf
- <SYSTEM32>\spaceman.exe.inf
- <SYSTEM32>\spatialaudiolicensesrv.exe.inf
- <SYSTEM32>\spectrum.exe.inf
- <SYSTEM32>\spoolsv.exe.inf
- <SYSTEM32>\sppextcomobj.exe.inf
- <SYSTEM32>\sppsvc.exe.inf
- <SYSTEM32>\srdelayed.exe.inf
- <SYSTEM32>\srtasks.exe.inf
- <SYSTEM32>\stordiag.exe.inf
- <SYSTEM32>\subst.exe.inf
- <SYSTEM32>\sxstrace.exe.inf
- <SYSTEM32>\syncappvpublishingserver.exe.inf
- <SYSTEM32>\synchost.exe.inf
- <SYSTEM32>\sysreseterr.exe.inf
- <SYSTEM32>\systeminfo.exe.inf
- <SYSTEM32>\systempropertiesadvanced.exe.inf
- <SYSTEM32>\systempropertiescomputername.exe.inf
- <SYSTEM32>\systempropertiesdataexecutionprevention.exe.inf
- <SYSTEM32>\systempropertieshardware.exe.inf
- <SYSTEM32>\systempropertiesperformance.exe.inf
- <SYSTEM32>\systempropertiesprotection.exe.inf
- <SYSTEM32>\systempropertiesremote.exe.inf
- <SYSTEM32>\systemreset.exe.inf
- <SYSTEM32>\systemsettingsadminflows.exe.inf
- <SYSTEM32>\systemsettingsbroker.exe.inf
- <SYSTEM32>\systemsettingsremovedevice.exe.inf
- <SYSTEM32>\systemuwplauncher.exe.inf
- <SYSTEM32>\systray.exe.inf
- <SYSTEM32>\tabcal.exe.inf
- <SYSTEM32>\takeown.exe.inf
- <SYSTEM32>\tapiunattend.exe.inf
- <SYSTEM32>\tar.exe.inf
- <SYSTEM32>\taskhostw.exe.inf
- <SYSTEM32>\taskkill.exe.inf
- <SYSTEM32>\tasklist.exe.inf
- <SYSTEM32>\taskmgr.exe.inf
- <SYSTEM32>\tcblaunch.exe.inf
- <SYSTEM32>\tcmsetup.exe.inf
- <SYSTEM32>\tcpsvcs.exe.inf
- <SYSTEM32>\thumbnailextractionhost.exe.inf
- <SYSTEM32>\tieringengineservice.exe.inf
- <SYSTEM32>\timeout.exe.inf
- <SYSTEM32>\tokenbrokercookies.exe.inf
- <SYSTEM32>\tpminit.exe.inf
- <SYSTEM32>\tpmtool.exe.inf
- <SYSTEM32>\tpmvscmgr.exe.inf
- <SYSTEM32>\tpmvscmgrsvr.exe.inf
- <SYSTEM32>\tracerpt.exe.inf
- <SYSTEM32>\tracert.exe.inf
- <SYSTEM32>\tscon.exe.inf
- <SYSTEM32>\tsdiscon.exe.inf
- <SYSTEM32>\tskill.exe.inf
- <SYSTEM32>\tstheme.exe.inf
- <SYSTEM32>\tswbprxy.exe.inf
- <SYSTEM32>\ttdinject.exe.inf
- <SYSTEM32>\tttracer.exe.inf
- <SYSTEM32>\typeperf.exe.inf
- <SYSTEM32>\tzsync.exe.inf
- <SYSTEM32>\tzutil.exe.inf
- <SYSTEM32>\ucsvc.exe.inf
- <SYSTEM32>\uevagentpolicygenerator.exe.inf
- <SYSTEM32>\uevappmonitor.exe.inf
- <SYSTEM32>\uevtemplatebaselinegenerator.exe.inf
- <SYSTEM32>\uevtemplateconfigitemgenerator.exe.inf
- <SYSTEM32>\uimgrbroker.exe.inf
- <SYSTEM32>\unlodctr.exe.inf
- <SYSTEM32>\unregmp2.exe.inf
- <SYSTEM32>\upgraderesultsui.exe.inf
- <SYSTEM32>\upnpcont.exe.inf
- <SYSTEM32>\useraccountbroker.exe.inf
- <SYSTEM32>\useraccountcontrolsettings.exe.inf
- <SYSTEM32>\userinit.exe.inf
- <SYSTEM32>\usoclient.exe.inf
- <SYSTEM32>\usocoreworker.exe.inf
- <SYSTEM32>\utcdecoderhost.exe.inf
- <SYSTEM32>\utilman.exe.inf
- <SYSTEM32>\vaultcmd.exe.inf
- <SYSTEM32>\vds.exe.inf
- <SYSTEM32>\vdsldr.exe.inf
- <SYSTEM32>\verclsid.exe.inf
- <SYSTEM32>\verifier.exe.inf
- <SYSTEM32>\verifiergui.exe.inf
- <SYSTEM32>\vssadmin.exe.inf
- <SYSTEM32>\vssvc.exe.inf
- <SYSTEM32>\w32tm.exe.inf
- <SYSTEM32>\waasmedicagent.exe.inf
- <SYSTEM32>\waitfor.exe.inf
- <SYSTEM32>\wallpaperhost.exe.inf
- <SYSTEM32>\wbadmin.exe.inf
- <SYSTEM32>\wbengine.exe.inf
- <SYSTEM32>\wecutil.exe.inf
- <SYSTEM32>\werfault.exe.inf
- <SYSTEM32>\werfaultsecure.exe.inf
- <SYSTEM32>\wermgr.exe.inf
- <SYSTEM32>\wevtutil.exe.inf
- <SYSTEM32>\wextract.exe.inf
- <SYSTEM32>\wfs.exe.inf
- <SYSTEM32>\where.exe.inf
- <SYSTEM32>\whoami.exe.inf
- <SYSTEM32>\wiaacmgr.exe.inf
- <SYSTEM32>\wiawow64.exe.inf
- <SYSTEM32>\wifitask.exe.inf
- <SYSTEM32>\wimserv.exe.inf
- <SYSTEM32>\winbiodatamodeloobe.exe.inf
- <SYSTEM32>\windows.media.backgroundplayback.exe.inf
- <SYSTEM32>\windows.warp.jitservice.exe.inf
- <SYSTEM32>\windowsactiondialog.exe.inf
- <SYSTEM32>\windowsupdateelevatedinstaller.exe.inf
- <SYSTEM32>\wininit.exe.inf
- <SYSTEM32>\winload.exe.inf
- <SYSTEM32>\winresume.exe.inf
- <SYSTEM32>\winrs.exe.inf
- <SYSTEM32>\winrshost.exe.inf
- <SYSTEM32>\winrtnetmuahostserver.exe.inf
- <SYSTEM32>\winsat.exe.inf
- <SYSTEM32>\winver.exe.inf
- <SYSTEM32>\wkspbroker.exe.inf
- <SYSTEM32>\wksprt.exe.inf
- <SYSTEM32>\wlanext.exe.inf
- <SYSTEM32>\wlrmdr.exe.inf
- <SYSTEM32>\wmpdmc.exe.inf
- <SYSTEM32>\workfolders.exe.inf
- <SYSTEM32>\wowreg32.exe.inf
- <SYSTEM32>\wpcmon.exe.inf
- <SYSTEM32>\wpctok.exe.inf
- <SYSTEM32>\wpdshextautoplay.exe.inf
- <SYSTEM32>\wpnpinst.exe.inf
- <SYSTEM32>\wpr.exe.inf
- <SYSTEM32>\write.exe.inf
- <SYSTEM32>\wscadminui.exe.inf
- <SYSTEM32>\wscollect.exe.inf
- <SYSTEM32>\wscript.exe.inf
- <SYSTEM32>\wsmanhttpconfig.exe.inf
- <SYSTEM32>\wsmprovhost.exe.inf
- <SYSTEM32>\wsqmcons.exe.inf
- <SYSTEM32>\wsreset.exe.inf
- <SYSTEM32>\wuapihost.exe.inf
- <SYSTEM32>\wuauclt.exe.inf
- <SYSTEM32>\wudfcompanionhost.exe.inf
- <SYSTEM32>\wudfhost.exe.inf
- <SYSTEM32>\wusa.exe.inf
- <SYSTEM32>\wwahost.exe.inf
- <SYSTEM32>\xblgamesavetask.exe.inf
- <SYSTEM32>\xcopy.exe.inf
- <SYSTEM32>\xwizard.exe.inf
- %APPDATA%\microsoft\windows\start menu\programs\startup\svchost.exe
- <Имя диска съемного носителя>:\systemservice.exe
- 'fi###.catbox.moe':443
- 'cd#.##scordapp.com':443
- 'fi###.catbox.moe':443
- 'cd#.##scordapp.com':443
- DNS ASK fi###.catbox.moe
- DNS ASK cd#.##scordapp.com
- '<SYSTEM32>\cmd.exe' /c schtasks /create /tn "WindowsService" /tr "\"<Полный путь к файлу>\"" /sc ONLOGON /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "WindowsService" /tr "\"<Полный путь к файлу>\"" /sc ONLOGON /rl HIGHEST /f
- '<SYSTEM32>\cmd.exe' /c schtasks /create /tn "WindowsServiceTask" /tr "\"<Полный путь к файлу>\"" /sc ONSTART /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "WindowsServiceTask" /tr "\"<Полный путь к файлу>\"" /sc ONSTART /rl HIGHEST /f
- '<SYSTEM32>\cmd.exe' /c schtasks /create /tn "WindowsServiceDaily" /tr "\"<Полный путь к файлу>\"" /sc DAILY /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "WindowsServiceDaily" /tr "\"<Полный путь к файлу>\"" /sc DAILY /rl HIGHEST /f
- '<SYSTEM32>\cmd.exe' /c bcdedit /set {bootmgr} path "<SYSTEM32>\svchost.exe"
- '<SYSTEM32>\bcdedit.exe' /set {bootmgr} path "<SYSTEM32>\svchost.exe"
- '<SYSTEM32>\cmd.exe' /c bcdedit /create /d "Windows Service" /application bootsector
- '<SYSTEM32>\bcdedit.exe' /create /d "Windows Service" /application bootsector