Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\msimg] 'DllName' = '<SYSTEM32>\msvidc16.dll'
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\windows NT\CurrentVersion\winlogon\Notify\msimg" /v Impersonate /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\windows NT\CurrentVersion\winlogon\Notify\msimg" /v StartShell /t REG_SZ /d msimg /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\windows NT\CurrentVersion\winlogon\Notify\msimg" /v Asynchronous /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\windows NT\CurrentVersion\winlogon\Notify\msimg" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\windows NT\CurrentVersion\winlogon\Notify\msimg" /v DllName /t REG_SZ /d <SYSTEM32>\msvidc16.dll /f
- <SYSTEM32>\msvidc16.dll
- <SYSTEM32>\msvidc16.dll.jie
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'