Техническая информация
- [<HKLM>\SOFTWARE\Classes\nntp\shell\open\command] '' = '"%ProgramFiles%\Windows Mail\WinMail.exe" /newsurl:"%1"'
- [<HKLM>\SOFTWARE\Classes\snews\shell\open\command] '' = '"%ProgramFiles%\Windows Mail\WinMail.exe" /newsurl:"%1"'
- [<HKLM>\SOFTWARE\Classes\mailto\shell\open\command] '' = '"%ProgramFiles%\Windows Mail\WinMail.exe" /mailurl:"%1"'
- [<HKLM>\SOFTWARE\Classes\news\shell\open\command] '' = '"%ProgramFiles%\Windows Mail\WinMail.exe" /newsurl:"%1"'
- '<SYSTEM32>\xcopy.exe' /E /S /Q "conf" "\Microsoft\"
- '<SYSTEM32>\cacls.exe' %ProgramFiles%\ /E /P %USERNAME%:F
- '<SYSTEM32>\xcopy.exe' /E /S /Q /H "progr" "%ProgramFiles%"
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\RarSFX0\wm.bat" "
- '%WINDIR%\regedit.exe' /s "Windows Mail.reg"
- '<SYSTEM32>\xcopy.exe' /Q /Y "msidcrl30.dll" "<SYSTEM32>"
- C:\Microsoft\Windows Mail\Stationery\Hand Prints.htm
- C:\Microsoft\Windows Mail\Stationery\grid_(inch).wmf
- C:\Microsoft\Windows Mail\Stationery\Memo.emf
- C:\Microsoft\Windows Mail\Stationery\HandPrints.jpg
- C:\Microsoft\Windows Mail\Stationery\grid_(cm).wmf
- C:\Microsoft\Windows Mail\Stationery\Graph.emf
- C:\Microsoft\Windows Mail\Stationery\Genko_2.emf
- C:\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg
- C:\Microsoft\Windows Mail\Stationery\Green Bubbles.htm
- C:\Microsoft\Windows Mail\Stationery\Peacock.htm
- C:\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg
- C:\Microsoft\Windows Mail\Stationery\Pine_Lumber.jpg
- C:\Microsoft\Windows Mail\Stationery\Peacock.jpg
- C:\Microsoft\Windows Mail\Stationery\Orange Circles.htm
- C:\Microsoft\Windows Mail\Stationery\Month_Calendar.emf
- C:\Microsoft\Windows Mail\Stationery\Monet.jpg
- C:\Microsoft\Windows Mail\Stationery\Notebook.jpg
- C:\Microsoft\Windows Mail\Stationery\Music.emf
- C:\Microsoft\Windows Mail\edbres00002.jrs
- C:\Microsoft\Windows Mail\edbres00001.jrs
- C:\Microsoft\Windows Mail\WindowsMail.MSMessageStore
- C:\Microsoft\Windows Mail\oeold.xml
- C:\Microsoft\Windows Mail\edb00001.log
- <SYSTEM32>\msidcrl30.dll
- %HOMEPATH%\Desktop\Windows Mail.lnk
- C:\Microsoft\Windows Mail\edb.log
- C:\Microsoft\Windows Mail\edb.chk
- C:\Microsoft\Windows Mail\Stationery\Garden.htm
- C:\Microsoft\Windows Mail\Stationery\Dotted_Lines.emf
- C:\Microsoft\Windows Mail\Stationery\Genko_1.emf
- C:\Microsoft\Windows Mail\Stationery\Garden.jpg
- C:\Microsoft\Windows Mail\Stationery\Connectivity.gif
- C:\Microsoft\Windows Mail\Stationery\Bears.jpg
- C:\Microsoft\Windows Mail\Stationery\Bears.htm
- C:\Microsoft\Windows Mail\Stationery\Cave_Drawings.gif
- C:\Microsoft\Windows Mail\Stationery\Blue_Gradient.jpg
- C:\Microsoft\Windows Mail\Stationery\Pretty_Peacock.jpg
- %ProgramFiles%\Windows Mail\wab.exe
- %ProgramFiles%\Windows Mail\OESpamFilter.dll
- %ProgramFiles%\Windows Mail\wabimp.dll
- %ProgramFiles%\Windows Mail\wabfind.dll
- %ProgramFiles%\Windows Mail\OESpamFilter.dat
- %ProgramFiles%\Windows Mail\msoe.dll
- C:\Microsoft\Windows Mail\Stationery\Wrinkled_Paper.gif
- %ProgramFiles%\Windows Mail\oeimport.dll
- %ProgramFiles%\Windows Mail\MSOERES.dll
- %ProgramFiles%\Windows Mail\pt-PT\msoeres.dll.mui
- %ProgramFiles%\Windows Mail\pt-BR\WinMail.exe.mui
- %ProgramFiles%\Windows Mail\pt-PT\WinMail.exe.mui
- %ProgramFiles%\Windows Mail\pt-PT\WindowsMailGadget.exe.mui
- %ProgramFiles%\Windows Mail\pt-BR\WindowsMailGadget.exe.mui
- %ProgramFiles%\Windows Mail\WindowsMailGadget.exe
- %ProgramFiles%\Windows Mail\wabmig.exe
- %ProgramFiles%\Windows Mail\pt-BR\msoeres.dll.mui
- %ProgramFiles%\Windows Mail\WinMail.exe
- C:\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg
- C:\Microsoft\Windows Mail\Stationery\Shades of Blue.htm
- C:\Microsoft\Windows Mail\Stationery\Small_News.jpg
- C:\Microsoft\Windows Mail\Stationery\Shorthand.emf
- C:\Microsoft\Windows Mail\Stationery\Seyes.emf
- C:\Microsoft\Windows Mail\Stationery\Roses.htm
- C:\Microsoft\Windows Mail\Stationery\Psychedelic.jpg
- C:\Microsoft\Windows Mail\Stationery\Sand_Paper.jpg
- C:\Microsoft\Windows Mail\Stationery\Roses.jpg
- C:\Microsoft\Windows Mail\Stationery\Tiki.gif
- C:\Microsoft\Windows Mail\Stationery\Tanspecks.jpg
- C:\Microsoft\Windows Mail\Stationery\White_Chocolate.jpg
- C:\Microsoft\Windows Mail\Stationery\To_Do_List.emf
- C:\Microsoft\Windows Mail\Stationery\Stucco.gif
- C:\Microsoft\Windows Mail\Stationery\SoftBlue.jpg
- C:\Microsoft\Windows Mail\Stationery\Soft Blue.htm
- C:\Microsoft\Windows Mail\Stationery\Stars.jpg
- C:\Microsoft\Windows Mail\Stationery\Stars.htm
- %TEMP%\RarSFX0\wm.bat
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Monet.jpg
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Memo.emf
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Music.emf
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Month_Calendar.emf
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\HandPrints.jpg
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\grid_(cm).wmf
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\GreenBubbles.jpg
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Hand Prints.htm
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\grid_(inch).wmf
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Pretty_Peacock.jpg
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Pine_Lumber.jpg
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Roses.htm
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Psychedelic.jpg
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Peacock.jpg
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Orange Circles.htm
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Notebook.jpg
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Peacock.htm
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\OrangeCircles.jpg
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Bears.htm
- %TEMP%\RarSFX0\conf\Windows Mail\oeold.xml
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Blue_Gradient.jpg
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Bears.jpg
- %TEMP%\RarSFX0\conf\Windows Mail\edbres00002.jrs
- %TEMP%\RarSFX0\conf\Windows Mail\edb.log
- %TEMP%\RarSFX0\conf\Windows Mail\edb.chk
- %TEMP%\RarSFX0\conf\Windows Mail\edbres00001.jrs
- %TEMP%\RarSFX0\conf\Windows Mail\edb00001.log
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Genko_2.emf
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Genko_1.emf
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Green Bubbles.htm
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Graph.emf
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Garden.jpg
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Connectivity.gif
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Cave_Drawings.gif
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Garden.htm
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Dotted_Lines.emf
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Roses.jpg
- %TEMP%\RarSFX0\progr\Windows Mail\pt-BR\WinMail.exe.mui
- %TEMP%\RarSFX0\progr\Windows Mail\pt-BR\WindowsMailGadget.exe.mui
- %TEMP%\RarSFX0\progr\Windows Mail\pt-PT\WindowsMailGadget.exe.mui
- %TEMP%\RarSFX0\progr\Windows Mail\pt-PT\msoeres.dll.mui
- %TEMP%\RarSFX0\progr\Windows Mail\pt-BR\msoeres.dll.mui
- %TEMP%\RarSFX0\progr\Windows Mail\oeimport.dll
- %TEMP%\RarSFX0\progr\Windows Mail\MSOERES.dll
- %TEMP%\RarSFX0\progr\Windows Mail\OESpamFilter.dll
- %TEMP%\RarSFX0\progr\Windows Mail\OESpamFilter.dat
- %TEMP%\RarSFX0\progr\Windows Mail\WinMail.exe
- %TEMP%\RarSFX0\progr\Windows Mail\WindowsMailGadget.exe
- %TEMP%\RarSFX0\Windows Mail.reg
- %TEMP%\RarSFX0\msidcrl30.dll
- %TEMP%\RarSFX0\progr\Windows Mail\wabmig.exe
- %TEMP%\RarSFX0\progr\Windows Mail\wab.exe
- %TEMP%\RarSFX0\progr\Windows Mail\pt-PT\WinMail.exe.mui
- %TEMP%\RarSFX0\progr\Windows Mail\wabimp.dll
- %TEMP%\RarSFX0\progr\Windows Mail\wabfind.dll
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Soft Blue.htm
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Small_News.jpg
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Stars.htm
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\SoftBlue.jpg
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Shorthand.emf
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Seyes.emf
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Sand_Paper.jpg
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\ShadesOfBlue.jpg
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Shades of Blue.htm
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Wrinkled_Paper.gif
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\White_Chocolate.jpg
- %TEMP%\RarSFX0\progr\Windows Mail\msoe.dll
- %TEMP%\RarSFX0\conf\Windows Mail\WindowsMail.MSMessageStore
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\To_Do_List.emf
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Stucco.gif
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Stars.jpg
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Tiki.gif
- %TEMP%\RarSFX0\conf\Windows Mail\Stationery\Tanspecks.jpg
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''