Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'dxcap' = '%TEMP%\dxcap.exe '
- %HOMEPATH%\Start Menu\Programs\Startup\dxcap.lnk
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe'
- '%TEMP%\dxcap.exe' /AutoIt3ExecuteScript "%TEMP%\coded2"
- '%TEMP%\dxcap.exe'
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
- %TEMP%\test.txt
- %TEMP%\dxcap.exe
- %TEMP%\coded2
- 'vi####h.mooo.com':6677
- DNS ASK vi####h.mooo.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''