Техническая информация
- [<HKLM>\SOFTWARE\Classes\AnchorClient\shell\open\command] '' = '"C:\AnchorClient\AnchorClient.exe" "%1"'
- C:\AnchorClient\CheckAnchorClientV2.bat
- C:\AnchorClient\ssleay32.dll
- C:\AnchorClient\libeay32.dll
- C:\AnchorClient\CheckAnchorClient\log.txt
- %TEMP%\nsv2.tmp\ns3.tmp
- %TEMP%\nsv2.tmp\nsExec.dll
- C:\AnchorClient\WinSCP.exe
- C:\AnchorClient\AnchorRDP.exe
- C:\AnchorClient\AnchorSSO.exe
- C:\AnchorClient\AnchorClient.exe
- C:\AnchorClient\vncviewer.exe
- C:\AnchorClient\iconn.dat
- C:\AnchorClient\AnchorMP.exe
- %TEMP%\nsv2.tmp\ns3.tmp
- '%TEMP%\nsv2.tmp\ns3.tmp' cmd /c "C:\AnchorClient\CheckAnchorClientV2.bat"
- '<SYSTEM32>\reg.exe' query HKEY_CLASSES_ROOT\AnchorClient\shell\open\command
- '<SYSTEM32>\cmd.exe' /c "C:\AnchorClient\CheckAnchorClientV2.bat"