Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'wextract_cleanup0' = 'rundll32.exe <SYSTEM32>\advpack.dll,DelNodeRunDLL32 "%TEMP%\IXP000.TMP\"'
- %WINDIR%\assembly\tmp\QK6S24XG\mscorcfg.Resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\ConfigWizards.Resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\RegCode.Resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\mscorcfg.Resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\Regasm.resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\1041\repairRedist.htm
- %WINDIR%\assembly\tmp\9ZVWT7EB\Mscorlib.Resources.dll
- %WINDIR%\assembly\tmp\FHZAWAR9\RegCode.Resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\mscorrc.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\ShFusRes.dll
- <SYSTEM32>\mui\0411\mscoreer.dll
- %ProgramFiles%\Internet Explorer\MUI\0411\mscorier.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\System.Web.Mobile.resources.dll
- %WINDIR%\assembly\tmp\PE0FIGMD\System.Web.Mobile.resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\aspnet_rc.dll
- %WINDIR%\assembly\tmp\N2I5X44Z\System.Design.Resources.dll
- %WINDIR%\assembly\tmp\7964J29Q\System.Drawing.Resources.dll
- %WINDIR%\assembly\tmp\34SP6UG4\System.Resources.dll
- %WINDIR%\assembly\tmp\2HH530WL\System.Data.Resources.dll
- %WINDIR%\assembly\tmp\UEWUBJP5\System.Web.Services.Resources.dll
- %WINDIR%\assembly\tmp\P2H1T73M\System.Windows.Forms.Resources.dll
- %WINDIR%\assembly\tmp\XBT79W4P\System.xml.Resources.dll
- %WINDIR%\assembly\tmp\X7NI80ZT\System.Messaging.Resources.dll
- %WINDIR%\assembly\tmp\EG6O8MIL\System.Drawing.design.Resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\caspol.resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\InstallUtil.resources.dll
- %WINDIR%\assembly\tmp\91QMYRJ5\System.Configuration.Install.Resources.dll
- %WINDIR%\assembly\tmp\6J0RO9RB\System.Management.Resources.dll
- %WINDIR%\assembly\tmp\YZ73ZS7Y\System.runtime.remoting.Resources.dll
- %WINDIR%\assembly\tmp\NKEKANFS\System.Runtime.Serialization.Formatters.Soap.Resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\MUI\0411\mscorsecr.dll
- %WINDIR%\assembly\tmp\7964J29Q\__AssemblyInfo__.ini
- %WINDIR%\assembly\tmp\X7NI80ZT\__AssemblyInfo__.ini
- %WINDIR%\assembly\tmp\34SP6UG4\__AssemblyInfo__.ini
- %WINDIR%\assembly\tmp\N2I5X44Z\__AssemblyInfo__.ini
- %WINDIR%\assembly\tmp\P2H1T73M\__AssemblyInfo__.ini
- %WINDIR%\assembly\tmp\XBT79W4P\__AssemblyInfo__.ini
- %WINDIR%\assembly\tmp\2HH530WL\__AssemblyInfo__.ini
- %WINDIR%\assembly\tmp\QK6S24XG\__AssemblyInfo__.ini
- %WINDIR%\assembly\tmp\YZ73ZS7Y\__AssemblyInfo__.ini
- %WINDIR%\assembly\tmp\NKEKANFS\__AssemblyInfo__.ini
- %WINDIR%\assembly\tmp\PE0FIGMD\__AssemblyInfo__.ini
- %WINDIR%\assembly\tmp\6J0RO9RB\__AssemblyInfo__.ini
- %WINDIR%\assembly\tmp\9ZVWT7EB\__AssemblyInfo__.ini
- %WINDIR%\assembly\tmp\91QMYRJ5\__AssemblyInfo__.ini
- %WINDIR%\assembly\tmp\EG6O8MIL\__AssemblyInfo__.ini
- %ALLUSERSPROFILE%\Start Menu\Programs\Administrative Tools\Microsoft .NET Framework 1.1 ウィザード.lnk
- %ALLUSERSPROFILE%\Start Menu\Programs\Administrative Tools\Microsoft .NET Framework 1.1 構成.lnk
- %WINDIR%\assembly\tmp\W0SY98BR\__AssemblyInfo__.ini
- %WINDIR%\Installer\{AD0DDEC6-4798-4DE5-87DC-4367D694ED06}\ndpsetup.ico
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\1041\WizardsShortcut.txt
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\1041\ConfigShortcut.txt
- %WINDIR%\Installer\2436c.msi
- %WINDIR%\assembly\tmp\0WNCHLY4\__AssemblyInfo__.ini
- %WINDIR%\assembly\tmp\DSUIB6QX\__AssemblyInfo__.ini
- %WINDIR%\assembly\tmp\9BYLE24I\__AssemblyInfo__.ini
- %WINDIR%\assembly\tmp\UEWUBJP5\__AssemblyInfo__.ini
- %WINDIR%\assembly\tmp\TVUYJGJ7\__AssemblyInfo__.ini
- %WINDIR%\assembly\tmp\9B1A5SV5\__AssemblyInfo__.ini
- %WINDIR%\assembly\tmp\VKQDAJNW\__AssemblyInfo__.ini
- %WINDIR%\assembly\tmp\FHZAWAR9\__AssemblyInfo__.ini
- %WINDIR%\assembly\tmp\9BYLE24I\System.Web.Resources.dll
- %WINDIR%\Installer\2436a.ipi
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\INDEX.BTR
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\INDEX.MAP
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\$WinMgmt.CFG
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SAM
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\ComDb.Dat
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\domain.txt
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING.VER
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\OBJECTS.MAP
- C:\Config.Msi\2436b.rbs
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\1041\Vsavb7rtUI.dll
- %WINDIR%\Installer\MSI2.tmp
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING1.MAP
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING2.MAP
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\OBJECTS.DATA
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-18
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-19
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-19
- %WINDIR%\Installer\MSI1.tmp
- %TEMP%\IXP000.TMP\langpac1.cab
- %TEMP%\IXP000.TMP\langpack.msi
- %WINDIR%\Installer\24368.msi
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-20
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SECURITY
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SOFTWARE
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SYSTEM
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_.DEFAULT
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-20
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2052111302-484763869-725345543-1003
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2052111302-484763869-725345543-1003
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\1041\alinkui.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\System.Security.Resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\System.EnterpriseServices.Resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\System.Windows.Forms.Resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\System.Runtime.Remoting.Resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\System.Design.Resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\System.DirectoryServices.Resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\System.ServiceProcess.Resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\System.Runtime.Serialization.Formatters.Soap.Resources.dll
- %WINDIR%\assembly\tmp\9B1A5SV5\System.Security.Resources.dll
- %WINDIR%\assembly\tmp\TVUYJGJ7\System.DirectoryServices.Resources.dll
- %WINDIR%\assembly\tmp\DSUIB6QX\System.ServiceProcess.Resources.dll
- %WINDIR%\assembly\tmp\VKQDAJNW\System.EnterpriseServices.Resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\System.Configuration.Install.Resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\System.Drawing.Design.Resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\System.Management.Resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\1041\vbc7ui.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\Microsoft.VisualBasic.resources.dll
- %WINDIR%\assembly\tmp\0WNCHLY4\Microsoft.VisualBasic.Resources.dll
- %WINDIR%\assembly\tmp\W0SY98BR\Microsoft.Jscript.Resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\1041\cscompui.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\Microsoft.JScript.Resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\JSC.Resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\mscorlib.resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\System.Data.Resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\System.Web.Services.Resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\System.xml.Resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\System.Messaging.Resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\system.resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\System.Web.Resources.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\JA\System.Drawing.Resources.dll
- %WINDIR%\Installer\2436a.ipi
- %TEMP%\IXP000.TMP\langpack.msi
- %TEMP%\IXP000.TMP\langpac1.cab
- %WINDIR%\Installer\24368.msi
- %WINDIR%\Installer\MSI1.tmp
- %WINDIR%\Installer\MSI2.tmp
- C:\Config.Msi\2436b.rbs
- '<SYSTEM32>\msiexec.exe' -Embedding ADDF151253BAD0F5B652DB0F039F96F1
- '<SYSTEM32>\msiexec.exe' /V
- '<SYSTEM32>\msiexec.exe' /qb /i langpack.msi