Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{74b5f312-b0f6-11d0-94ab-0080c74c7e95}] 'StubPath' = '%WINDIR%\web\wallpaper.pif'
- [<HKLM>\SYSTEM\ControlSet001\Services\RNetMeeting Remote] 'Start' = '00000002'
- '<SYSTEM32>\RNetMeeting Remote.exe'
- 'C:\ok.exe'
- 'C:\server.exe'
- '<SYSTEM32>\cmd.exe' /c c:\del_fxuvnme.bat
- '<SYSTEM32>\conime.exe'
- <SYSTEM32>\conime.exe
- %TEMP%\_eviip.tmp
- %WINDIR%\Fonts\775d4ef4d8803e9e347756f154f6c574.dat
- C:\del_fxuvnme.bat
- %TEMP%\BClib\krnln.fnr
- %TEMP%\BClib\krnln.fne
- %TEMP%\BClib\Exmlrpc.fne
- %TEMP%\BClib\dp1.fne
- <SYSTEM32>\RNetMeeting Remote.dll
- %WINDIR%\Web\wallpaper.pif
- C:\ok.exe
- C:\server.exe
- %TEMP%\E_4\krnln.fnr
- <SYSTEM32>\RNetMeeting Remote.exe
- %TEMP%\E_4\dp1.fne
- %TEMP%\E_4\Exmlrpc.fne
- <SYSTEM32>\RNetMeeting Remote.dll
- %WINDIR%\Web\wallpaper.pif
- <SYSTEM32>\RNetMeeting Remote.exe
- C:\ok.exe
- C:\server.exe
- 'yw##.gnway.net':19820
- 'yw##.3322.org':19820
- '81###5.3322.org':1764
- DNS ASK yw##.gnway.net
- DNS ASK yw##.3322.org
- DNS ASK 81###5.3322.org
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''