Техническая информация
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\WinLogon] 'GinaDLL' = 'VBoxGINA.dll'
- %WINDIR%\win.ini
- %WINDIR%\syswow64\nslookup.exe
- %TEMP%\nsmbcef.tmp
- %TEMP%\ermine
- %TEMP%\nswbd2e.tmp\nsexec.dll
- %TEMP%\times\hw-consumer.h
- %TEMP%\times\clickoncevsinstaller04.gif
- %APPDATA%\locations\query\genasm.exe
- %APPDATA%\locations\query\scope20.il
- %APPDATA%\locations\query\ooo-web.svg
- %TEMP%\misrules.dll
- %APPDATA%\locations\query\regcap.exe
- %APPDATA%\locations\query\xpathexpr.cs
- %APPDATA%\locations\query\doc-old.tmac
- %APPDATA%\locations\query\face-heart-symbolic.svg
- %APPDATA%\locations\query\vnd.oasis.opendocument.text-flat-xml.xml
- %APPDATA%\locations\query\libgoa-1.0.so.0
- %APPDATA%\locations\query\co3752setvalueviii.cs
- %APPDATA%\locations\query\vcmergemodules.xml
- %APPDATA%\locations\query\vsteamcoreui.dll
- %TEMP%\nswbd2e.tmp\system.dll
- '%WINDIR%\syswow64\nslookup.exe'