Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\dfge] 'ImagePath' = '%PROGRAM_FILES%\msdn\VectorMonitor.pas'
- [<HKLM>\SYSTEM\ControlSet001\Services\dfge] 'Start' = '00000001'
- <SYSTEM32>\hknpp.exe
- <SYSTEM32>\wxqqq.exe
- %TEMP%\tmm167.tmp
- <SYSTEM32>\uqikp.exe
- <SYSTEM32>\sc.exe stop ZhuDongFangYu
- <SYSTEM32>\sc.exe delete ZhuDongFangYu
- <SYSTEM32>\sc.exe stop 360rp
- <SYSTEM32>\rundll32.exe %TEMP%\Hyt1354.tmp,Main
- <SYSTEM32>\arp.exe -s 10.0.0.1 00-00-00-00-00-00
- <SYSTEM32>\runonce.exe -r
- <SYSTEM32>\arp.exe -d
- MCAGENT.EXE
- <SYSTEM32>\uqikp.exe
- %TEMP%\Hyt1354.tmp
- %PROGRAM_FILES%\msdn\VectorMonitor.pas
- <SYSTEM32>\wxqqq.exe
- <SYSTEM32>\hknpp.exe
- %PROGRAM_FILES%\AAV\CDriver.sys
- <Служебный элемент>
- %PROGRAM_FILES%\msdn\VectorMonitor.sys
- %PROGRAM_FILES%\msdn\VectorMonitor.inf
- %TEMP%\tmm167.tmp
- <DRIVERS>\SET3.tmp
- %WINDIR%\inf\oem3.PNF
- %WINDIR%\inf\oem3.inf
- <SYSTEM32>\uqikp.exe
- <SYSTEM32>\hknpp.exe
- <DRIVERS>\VectorMonitor.sys
- %PROGRAM_FILES%\msdn\VectorMonitor.inf
- %PROGRAM_FILES%\msdn\VectorMonitor.sys
- %PROGRAM_FILES%\msdn\VectorMonitor.pas
- <DRIVERS>\SET3.tmp в <DRIVERS>\VectorMonitor.sys
- ClassName: 'Shell_TrayWnd' WindowName: ''