Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\updater32x64] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\updater64x32] 'Start' = '00000000'
- <SYSTEM32>\reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\windows32up" /v ImagePath /t REG_EXPAND_SZ /d "system32\drivers\sounddriveri.sys
- <SYSTEM32>\reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\windows32up" /v Start /t REG_DWORD /d "1
- <SYSTEM32>\reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\windows32up" /v ErrorControl /t REG_DWORD /d "0
- <SYSTEM32>\reg.exe add "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run" /v MsnMsgr Me/t REG_SZ /d "<SYSTEM32>\msnmmsgs.exe
- <SYSTEM32>\reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\windows32up" /v DisplayName /t REG_SZ /d "Micros Driver
- %TEMP%\tempsys211213
- <SYSTEM32>\bloccoppyyy1
- %TEMP%\systemp2323113
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\drv[1].jpg
- <DRIVERS>\sounddriveri.sys
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\hosts[1].txt
- '20#.#8.47.33':80
- 'www.im###ssions.cz':80
- 'localhost':1035
- 20#.#8.47.33/hosts.txt
- www.im###ssions.cz/en/izoc/m/drv.jpg
- DNS ASK www.im###ssions.cz
- '<IP-адрес в локальной сети>':1036