Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\wuauserv] 'Start' = '00000002'
- %ProgramFiles%\TerminalServer\logging\TerminalServer_uninstall.utf8.log
- C:\Documents and Settings\Default User\NTUSER.DAT.LOG
- C:\Documents and Settings\LocalService\NTUSER
- C:\Documents and Settings\NetworkService\NTUSER
- %HOMEPATH%\NTUSER
- %WINDIR%\Temp\Perflib_Perfdata_7e8.dat
- ClassName: 'StatusWindowClass' WindowName: ''
- '<SYSTEM32>\schtasks.exe' /delete /F /TN "tsvGuardian"
- '<SYSTEM32>\rundll32.exe' printui.dll,PrintUIEntry /dl /n "TerminalServer Printer" /q
- '<SYSTEM32>\spoolsv.exe'