Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'WinUpdate' = '<Полный путь к файлу>'
- %HOMEPATH%\desktop\advice_process.htm
- %HOMEPATH%\desktop\508softwareandos.doc
- %HOMEPATH%\desktop\archer.avi
- %HOMEPATH%\desktop\contoso.cer
- %HOMEPATH%\desktop\contosoroot.cer
- %HOMEPATH%\desktop\contoso_1.cer
- %HOMEPATH%\desktop\correct.avi
- %HOMEPATH%\desktop\glidescope_review_rev_010.docx
- %HOMEPATH%\desktop\join.avi
- %HOMEPATH%\desktop\pmd.cer
- %HOMEPATH%\desktop\sdksampleunprivdeveloper.cer
- %HOMEPATH%\desktop\sdszfo.docx
- %HOMEPATH%\desktop\testcertificate.cer
- %HOMEPATH%\desktop\tree_view.htm
- %HOMEPATH%\desktop\weeklysheet1215.doc
- %HOMEPATH%\documents\desktop.ini.locked
- %HOMEPATH%\desktop\508softwareandos.doc.locked
- %HOMEPATH%\desktop\advice_process.htm.locked
- %HOMEPATH%\desktop\archer.avi.locked
- %HOMEPATH%\desktop\desktop.ini.locked
- %HOMEPATH%\desktop\google chrome.lnk.locked
- %HOMEPATH%\desktop\telegram.lnk.locked
- %HOMEPATH%\pictures\camera roll\desktop.ini.locked
- %HOMEPATH%\pictures\desktop.ini.locked
- %HOMEPATH%\desktop\readme.txt
- %LOCALAPPDATA%\microsoft\windows\explorer\thumbcache_idx.db
- ClassName: 'TaskManagerWindow' WindowName: ''
- ClassName: '' WindowName: 'Process Explorer'
- ClassName: '' WindowName: 'Process Hacker'