Trojan.winrule
* Registry path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Window Rules Manager
HKEY_LOCAL_MACHINE\SOFTWARE\okwinrule
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinRuleSvc
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinRuleSvc2
* Files path
C\Program Files\winrule\Uninstall.exe
C\Program Files\winrule\WinRule.exe
C\Program Files\winrule\WinRuleSync.exe
C\Program Files\winrule\WinRuleSync_.exe
C\Program Files\winrule\winruletask.exe
C\Program Files\winrule\winruletask_.exe
C\Program Files\winrule\WinRule_.exe
|
|