Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'Virtual Java rn' = 'wintsv.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'Explorer Options3' = ''
- '<SYSTEM32>\wnksyt.exe' a
- '%TEMP%\NOD32.exe'
- '%TEMP%\Binder.exe'
- <SYSTEM32>\wnksyt.exe
- %TEMP%\NOD32.exe
- %TEMP%\eguiUpdate.dll
- <SYSTEM32>\vandeft.exe
- <SYSTEM32>\atipict.exe
- <SYSTEM32>\wintsv.exe
- %TEMP%\eguiDmon.dll
- %TEMP%\eguiAmon.dll
- %TEMP%\Binder.exe
- %TEMP%\eguiSmon.dll
- %TEMP%\eguiScan.dll
- %TEMP%\eguiEmon.dll
- <SYSTEM32>\atipict.exe
- <SYSTEM32>\vandeft.exe
- <SYSTEM32>\wnksyt.exe
- <SYSTEM32>\wintsv.exe
- <SYSTEM32>\atipict.exe
- <SYSTEM32>\vandeft.exe
- <SYSTEM32>\wnksyt.exe
- <SYSTEM32>\wintsv.exe
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'ESET Client Frame' WindowName: ''