Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\AarSvc_7961f7] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\AarSvc_7961f7] 'ImagePath' = 'cmd /c cd /d "<SYSTEM32>" && start "" "%ALLUSERSPROFILE%\MouseTuner\MouseTuner.exe"'
- 'AarSvc_7961f7' cmd /c cd /d "<SYSTEM32>" && start "" "%ALLUSERSPROFILE%\MouseTuner\MouseTuner.exe"
- %WINDIR%\syswow64\backgroundtaskhost.exe
- %ALLUSERSPROFILE%\mousetuner\session.csv
- %ALLUSERSPROFILE%\mousetuner\app.log
- %ALLUSERSPROFILE%\mousetuner\wab.exe
- %ALLUSERSPROFILE%\mousetuner\uftncqk.dll
- %ALLUSERSPROFILE%\mousetuner\cache.pmt
- %ALLUSERSPROFILE%\mousetuner\wab.exe в %ALLUSERSPROFILE%\mousetuner\mousetuner.exe
- 'lo###.live.com':443
- '45.###.#.159.360tray.net':8084
- 'lo###.live.com':443
- '45.###.#.159.360tray.net':8084
- DNS ASK lo###.live.com
- DNS ASK 45.###.#.159.360tray.net
- '%ALLUSERSPROFILE%\mousetuner\mousetuner.exe'
- '<SYSTEM32>\perceptionsimulation\perceptionsimulationservice.exe'
- '%WINDIR%\syswow64\backgroundtaskhost.exe'