Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\windows] 'Start' = '00000002'
- %WINDIR%\windows
- %CommonProgramFiles%\Microsoft Shared\MSInfo\3322setup.exe
- %CommonProgramFiles%\Microsoft Shared\MSInfo\2.vmp.exe
- <SYSTEM32>\cmd.exe /c %WINDIR%\uninstal.bat
- %TEMP%\GLG4.tmp
- %WINDIR%\windows
- %WINDIR%\uninstal.bat
- %TEMP%\~GLH0000.TMP
- %CommonProgramFiles%\Microsoft Shared\MSInfo\3322setup.jpg
- %CommonProgramFiles%\Microsoft Shared\MSInfo\2.vmp.jpg
- %TEMP%\GLK2.tmp
- %TEMP%\GLC1.tmp
- %WINDIR%\windows
- %CommonProgramFiles%\Microsoft Shared\MSInfo\2.vmp.exe
- 'ls##.3322.org':8000
- DNS ASK ls##.3322.org
- ClassName: 'Shell_TrayWnd' WindowName: ''