:q:
تغيرات في الريجستري انشاء
- Registry Keys Created: HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\WorkgroupCrawler HKU\ S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\ Windows\CurrentVersion\Explorer\WorkgroupCrawler\Shares
ملفات
C:\WINDOWS\SSVICHOSST.exe C:\WINDOWS\system32\SSVICHOSST.exe C:\WINDOWS\system32\autorun.ini
- Device Control Communication: File Control Code Times unnamed file 0x00390008 7 IDE#CdRomQEMU_QEMU_CD-ROM________________________0.9.____#4d51303030302033202020202020202020202020#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} 0x004D0008 1 MountPointManager 0x006D0008 2 STORAGE#Volume#1&30a96598&0&SignatureB15FB15FOffset7E00Length13F291800#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} 0x004D0008 1 MountPointManager 0x006D0034 4 :q::q::q: