¸

, ! .


»  ¸ »  »  ()


()

1 3 3

1

1. / .
2. , : , System, Explorer, svchost, taskmgr, winlogon.
3. .
4. :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_USERS\_\Software\Microsoft\Windows\CurrentVersion\Run
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run]


5. :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL

6. :
HKEY_USERS\S-1-5-21-2151830322-776356797-4068869133-2022\Software\Microsoft\Internet Explorer
HKEY_USERS\S-1-5-21-2151830322-776356797-4068869133-2022\Software\Microsoft\Internet Explorer\Main
HKEY_USERS\S-1-5-21-2151830322-776356797-4068869133-2022\Software\Microsoft\Internet Explorer\Search

Search.
__________________
, , , TFTP.EXE ( Windows, \WINDOWS\SYSTEM32\, \WINDOWS\SYSTEM32\DLLCACHE)

0

2

Windows Ctrl, , StartUp (), .

Image (2009-04-16 00:20:14)

0

3


»  ¸ »  »  ()