Техническая информация
- '<SYSTEM32>\sc.exe' delete hcmon
- '<SYSTEM32>\net.exe' stop vmusb
- '<SYSTEM32>\net.exe' stop hcmon
- '<SYSTEM32>\net1.exe' stop hcmon
- '<SYSTEM32>\net1.exe' stop vmusb
- '<SYSTEM32>\net1.exe' user __vmware_user__ /delete
- '<SYSTEM32>\net1.exe' localgroup __vmware__ /delete
- '<SYSTEM32>\sc.exe' delete vmusb
- '<SYSTEM32>\reg.exe' delete "HKEY_LOCAL_MACHINE\SOFTWARE\VMware, Inc." /f
- '<SYSTEM32>\sc.exe' delete VMnetuserif
- '<SYSTEM32>\net1.exe' stop vmnetbridge
- '<SYSTEM32>\sc.exe' delete vmnetbridge
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\fzc.bat""
- '<SYSTEM32>\net.exe' stop vmnetbridge
- '<SYSTEM32>\net.exe' stop vmx86
- '<SYSTEM32>\net.exe' stop VMnetuserif
- '<SYSTEM32>\net1.exe' stop VMnetuserif
- '<SYSTEM32>\net1.exe' stop vmx86
- '<SYSTEM32>\sc.exe' delete vmx86
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\52flin[1]
- %TEMP%\1.tmp\fzc.bat
- %TEMP%\1.tmp\fzc.bat
- 'www.52##in.com':80
- 'localhost':1035
- www.52##in.com/
- DNS ASK www.52##in.com
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'IEFrame' WindowName: '(null)'
- ClassName: '' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'