Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\PortTalk] 'ImagePath' = 'System32\Drivers\PortTalk.sys'
- %TEMP%\RarSFX0\Victoria.exe
- %TEMP%\RarSFX0\whatsnew.rtf
- %TEMP%\RarSFX0\hidcon.exe
- %TEMP%\RarSFX0\porttalk.sys
- %TEMP%\RarSFX0\start.bat
- %TEMP%\RarSFX0\USB_SupportList.rtf
- %TEMP%\RarSFX0\vcr40.ini
- %TEMP%\RarSFX0\vichlp.rtf
- %TEMP%\RarSFX0\LOGS\eventlog.txt
- <DRIVERS>\PortTalk.sys
- %TEMP%\RarSFX0\LOGS\Passp_XXware Xirtual IDE Hard Drive_11000000000000000001.bin
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\RarSFX0\hidcon.exe' start.bat
- '%TEMP%\RarSFX0\Victoria.exe'
- '<SYSTEM32>\cmd.exe' /c start.bat