Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\services\sptd] 'Start' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\services\sptd] 'ImagePath' = '<DRIVERS>\sptd.sys'
- '%TEMP%\SPTDinst.exe' add /q
- '%APPDATA%\Roaming\Setup.exe' /S
- '<SYSTEM32>\vssvc.exe'
- '<SYSTEM32>\svchost.exe' -k swprv
- '<SYSTEM32>\ipconfig.exe' /release *
- '<SYSTEM32>\mobsync.exe' -Embedding
- %BOOT_VOL%\Boot\BCD
- %BOOT_VOL%\Boot\BCD.LOG
- C:\System Volume Information\Syscache.hve.LOG1
- <DRIVERS>\sptd.sys
- C:\System Volume Information\Syscache.hve
- %TEMP%\SPTDinst.exe
- %APPDATA%\Roaming\Setup.exe
- %TEMP%\autC744.tmp
- %TEMP%\nsiD24D.tmp
- %TEMP%\nsxD26D.tmp\_InstUpdateOption.ini
- %TEMP%\nsxD26D.tmp\setuphlp.dll
- %APPDATA%\Roaming\Setup.exe
- %TEMP%\SPTDinst.exe
- %TEMP%\autC744.tmp
- 'localhost':5357
- 'localhost':60784
- ClassName: 'Shell_TrayWnd' WindowName: ''