Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\services\winpwrmng] 'Start' = '00000002'
- '%APPDATA%\Roaming\taskmng.exe'
- '%APPDATA%\Roaming\WinPowerService.exe'
- '%WINDIR%\InstallUtil.exe' %APPDATA%\Roaming\WinPowerService.exe
- '<SYSTEM32>\net1.exe' start winpwrmng
- '<SYSTEM32>\rundll32.exe' dfdts.dll,DfdGetDefaultPolicyAndSMART
- '<SYSTEM32>\sc.exe' query winpwrmng
- '<SYSTEM32>\find.exe' "RUNNING"
- %APPDATA%\Roaming\WinPowerService.InstallLog
- %APPDATA%\Roaming\WinPowerService.InstallState
- <LS_APPDATA>\Microsoft\Windows\Temporary Internet Files\BayanTelefonListesi.exe
- <Текущая директория>\InstallUtil.InstallLog
- %WINDIR%\InstallUtil.exe
- %APPDATA%\Roaming\taskmng.exe
- %APPDATA%\Roaming\WinPowerService.exe
- <Текущая директория>\InstallUtil.InstallLog
- %APPDATA%\Roaming\WinPowerService.InstallLog
- '21#.#36.92.3':8500
- '21#.#36.92.2':8500
- DNS ASK dn#.##ftncsi.com
- ClassName: 'MS_WebCheckMonitor' WindowName: '(null)'
- ClassName: 'OleMainThreadWndClass' WindowName: '(null)'
- ClassName: 'MouseZ' WindowName: 'Magellan MSWHEEL'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'