Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Security Windows' = '%PROGRAM_FILES%\Microsoft Security\Hooker.exe'
- '%PROGRAM_FILES%\Microsoft Security\Hooker.exe'
- '%PROGRAM_FILES%\Microsoft Security\registry.exe'
- Библиотека-обработчик для всех процессов: %PROGRAM_FILES%\Microsoft Security\HookLib.dll
- %PROGRAM_FILES%\Microsoft Security\Hooker.exe
- %PROGRAM_FILES%\Microsoft Security\Hooker.ini
- %PROGRAM_FILES%\Microsoft Security\HookLib.dll
- %PROGRAM_FILES%\Microsoft Security\Log.txt
- %PROGRAM_FILES%\Microsoft Security\registry.exe
- %PROGRAM_FILES%\Microsoft Security\History.txt
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'