Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Spooler] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\WinServerViewx] 'Start' = '00000002'
- '<SYSTEM32>\sys_temtrayx.exe'
- '<SYSTEM32>\cmd.exe' /c c:\del.bat
- '<SYSTEM32>\net1.exe' start WinServerViewx
- '<SYSTEM32>\sc.exe' create WinServerViewx binpath= "<SYSTEM32>\sys_temtrayx.exe" type= share start= auto displayname= "systemtrayx" depend= RPCSS/Tcpip/IPSec
- <SYSTEM32>\spoolsv.exe
- C:\bstemp.ini
- <SYSTEM32>\sys_temtrayxkaba.sub
- <SYSTEM32>\hz_sys_temtrayx.shd
- <SYSTEM32>\sys_temtrayx.txt
- <SYSTEM32>\sys_temtrayx.jpg
- C:\del.bat
- <SYSTEM32>\keyHook.dll
- <SYSTEM32>\sys_temtrayx.exe
- <SYSTEM32>\sys_temtrayx.ini
- <SYSTEM32>\hz_sys_temtrayx.dll
- %PROGRAM_FILES%\Internet Explorer\xiezai.cfg
- <SYSTEM32>\hz_sys_temtrayx.dat
- %PROGRAM_FILES%\Internet Explorer\xiezai.cfg
- <SYSTEM32>\sys_temtrayx.exe
- <SYSTEM32>\sys_temtrayx.ini
- C:\bstemp.ini
- <SYSTEM32>\hz_sys_temtrayx.dat
- 'li#####o2008.3322.org':8760
- DNS ASK li#####o2008.3322.org
- ClassName: 'MS_WINHELP' WindowName: ''