Техническая информация
- %TEMP%\nst5.tmp\ns19.tmp "netsh.exe" firewall delete allowedprogram "<Текущая директория>\DualDesk.exe" CURRENT
- %TEMP%\nst5.tmp\ns1A.tmp REG.EXE DELETE "HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\DualDesk-Server" /f
- %TEMP%\nst5.tmp\ns1B.tmp cmd.exe /C del /P /Q "%TEMP%\DD.txt"
- %TEMP%\nst5.tmp\ns18.tmp "netsh.exe" firewall delete allowedprogram "<Текущая директория>\DualDesk.exe" ALL
- %TEMP%\nst5.tmp\ns15.tmp REG.EXE DELETE "SYSTEM\CurrentControlSet\Services\DD_Service\Description" /f
- %TEMP%\nst5.tmp\ns16.tmp REG.EXE DELETE "SYSTEM\CurrentControlSet\Services\DD_Service\DependOnService" /f
- %TEMP%\nst5.tmp\ns17.tmp REG.EXE DELETE "SYSTEM\CurrentControlSet\Services\DD_Service" /f
- %TEMP%\nst5.tmp\ns1C.tmp cmd.exe /C RMDIR /S /Q "%TEMP%\DDTmp1"
- %TEMP%\nst5.tmp\ns21.tmp cmd.exe /C RMDIR /S /Q "%TEMP%\DDTmp2"
- %TEMP%\nst5.tmp\ns22.tmp cmd.exe /C RMDIR /S /Q "<Текущая директория>"
- %TEMP%\nst5.tmp\ns23.tmp cmd.exe /C RMDIR /S /Q "%HOMEPATH%\Local Settings\Temp"
- %TEMP%\nst5.tmp\ns20.tmp cmd.exe /C RMDIR /S /Q "%TEMP%\DDTmp1"
- %TEMP%\nst5.tmp\ns1D.tmp cmd.exe /C RMDIR /S /Q "%TEMP%\DDTmp2"
- %TEMP%\nst5.tmp\ns1E.tmp cmd.exe /C RMDIR /S /Q "%HOMEPATH%\Local Settings\Temp"
- %TEMP%\nst5.tmp\ns1F.tmp cmd.exe /C del /P /Q "%TEMP%\DD.txt"
- %TEMP%\nst5.tmp\ns14.tmp REG.EXE DELETE "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DD_Service" /f
- %TEMP%\nst5.tmp\ns9.tmp "tskill.exe" DDHelper
- %TEMP%\nst5.tmp\nsA.tmp "taskkill.exe" /F /IM DDHelper.exe /T
- %TEMP%\nst5.tmp\nsB.tmp "tskill.exe" DualDesk
- %TEMP%\nst5.tmp\ns8.tmp "net.exe" stop DD_Service
- %TEMP%\A~ADVANTIGu_.exe _?=<Текущая директория>\
- %TEMP%\nst5.tmp\ns6.tmp "sc.exe" delete DD_Service
- %TEMP%\nst5.tmp\ns7.tmp "sc.exe" delete DD_CAD
- %TEMP%\nst5.tmp\nsC.tmp "taskkill.exe" /F /IM DualDesk.exe /T
- %TEMP%\nst5.tmp\ns11.tmp REG.EXE DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\DDHelper" /f
- %TEMP%\nst5.tmp\ns12.tmp REG.EXE DELETE "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DD_Service\Security" /f
- %TEMP%\nst5.tmp\ns13.tmp REG.EXE DELETE "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DD_Service\Enum" /f
- %TEMP%\nst5.tmp\ns10.tmp REG.EXE DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\DDExe" /f
- %TEMP%\nst5.tmp\nsD.tmp REG.EXE DELETE "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DD-HideFileExt" /f
- %TEMP%\nst5.tmp\nsE.tmp REG.EXE DELETE "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DD-Hidden" /f
- %TEMP%\nst5.tmp\nsF.tmp REG.EXE DELETE "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DD-ShowSuperHidden" /f
- <SYSTEM32>\reg.exe DELETE "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DD_Service\Security" /f
- <SYSTEM32>\reg.exe DELETE "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DD_Service\Enum" /f
- <SYSTEM32>\reg.exe DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\DDHelper" /f
- <SYSTEM32>\reg.exe DELETE "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DD-ShowSuperHidden" /f
- <SYSTEM32>\reg.exe DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\DDExe" /f
- <SYSTEM32>\reg.exe DELETE "SYSTEM\CurrentControlSet\Services\DD_Service" /f
- <SYSTEM32>\reg.exe DELETE "HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\DualDesk-Server" /f
- <SYSTEM32>\reg.exe DELETE "SYSTEM\CurrentControlSet\Services\DD_Service\DependOnService" /f
- <SYSTEM32>\reg.exe DELETE "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DD_Service" /f
- <SYSTEM32>\reg.exe DELETE "SYSTEM\CurrentControlSet\Services\DD_Service\Description" /f
- <SYSTEM32>\net1.exe stop DD_Service
- <SYSTEM32>\tskill.exe DDHelper
- <SYSTEM32>\net.exe stop DD_Service
- <SYSTEM32>\sc.exe delete DD_Service
- <SYSTEM32>\sc.exe delete DD_CAD
- <SYSTEM32>\reg.exe DELETE "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DD-HideFileExt" /f
- <SYSTEM32>\reg.exe DELETE "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DD-Hidden" /f
- <SYSTEM32>\taskkill.exe /F /IM DualDesk.exe /T
- <SYSTEM32>\taskkill.exe /F /IM DDHelper.exe /T
- <SYSTEM32>\tskill.exe DualDesk
- %TEMP%\nst5.tmp\ns19.tmp
- %TEMP%\nst5.tmp\ns18.tmp
- <Текущая директория>\DD.txt
- %TEMP%\nst5.tmp\ns1A.tmp
- %TEMP%\nst5.tmp\ns17.tmp
- %TEMP%\nst5.tmp\ns14.tmp
- %TEMP%\nst5.tmp\ns13.tmp
- %TEMP%\nst5.tmp\ns16.tmp
- %TEMP%\nst5.tmp\ns15.tmp
- %TEMP%\nst5.tmp\ns21.tmp
- %TEMP%\nst5.tmp\ns20.tmp
- %TEMP%\nst5.tmp\ns23.tmp
- %TEMP%\nst5.tmp\ns22.tmp
- %TEMP%\nst5.tmp\ns1F.tmp
- %TEMP%\nst5.tmp\ns1C.tmp
- %TEMP%\nst5.tmp\ns1B.tmp
- %TEMP%\nst5.tmp\ns1E.tmp
- %TEMP%\nst5.tmp\ns1D.tmp
- %TEMP%\nst5.tmp\ns7.tmp
- %TEMP%\nst5.tmp\ns6.tmp
- %TEMP%\nst5.tmp\ns9.tmp
- %TEMP%\nst5.tmp\ns8.tmp
- %TEMP%\nst5.tmp\nsExec.dll
- %TEMP%\A~ADVANTIGu_.exe
- %TEMP%\nsy2.tmp
- %TEMP%\DD.txt
- %TEMP%\nsv4.tmp
- %TEMP%\nst5.tmp\ns10.tmp
- %TEMP%\nst5.tmp\nsF.tmp
- %TEMP%\nst5.tmp\ns12.tmp
- %TEMP%\nst5.tmp\ns11.tmp
- %TEMP%\nst5.tmp\nsE.tmp
- %TEMP%\nst5.tmp\nsB.tmp
- %TEMP%\nst5.tmp\nsA.tmp
- %TEMP%\nst5.tmp\nsD.tmp
- %TEMP%\nst5.tmp\nsC.tmp
- %TEMP%\DD.txt
- <Текущая директория>\DD.txt
- %TEMP%\nst5.tmp\ns1C.tmp
- %TEMP%\nst5.tmp\ns1B.tmp
- %TEMP%\nst5.tmp\ns18.tmp
- %TEMP%\nst5.tmp\ns17.tmp
- %TEMP%\nst5.tmp\ns1A.tmp
- %TEMP%\nst5.tmp\ns19.tmp
- %TEMP%\nst5.tmp\ns21.tmp
- %TEMP%\nst5.tmp\ns20.tmp
- %TEMP%\nst5.tmp\ns23.tmp
- %TEMP%\nst5.tmp\ns22.tmp
- %TEMP%\nst5.tmp\ns1E.tmp
- %TEMP%\nst5.tmp\ns1D.tmp
- %TEMP%\nst5.tmp\ns1F.tmp
- %TEMP%\nst5.tmp\nsExec.dll
- %TEMP%\nst5.tmp\ns16.tmp
- %TEMP%\nst5.tmp\nsB.tmp
- %TEMP%\nst5.tmp\nsA.tmp
- %TEMP%\nst5.tmp\nsD.tmp
- %TEMP%\nst5.tmp\nsC.tmp
- %TEMP%\nst5.tmp\ns7.tmp
- %TEMP%\nst5.tmp\ns6.tmp
- %TEMP%\nst5.tmp\ns9.tmp
- %TEMP%\nst5.tmp\ns8.tmp
- %TEMP%\nst5.tmp\ns13.tmp
- %TEMP%\nst5.tmp\ns12.tmp
- %TEMP%\nst5.tmp\ns15.tmp
- %TEMP%\nst5.tmp\ns14.tmp
- %TEMP%\nst5.tmp\nsF.tmp
- %TEMP%\nst5.tmp\nsE.tmp
- %TEMP%\nst5.tmp\ns11.tmp
- %TEMP%\nst5.tmp\ns10.tmp
- ClassName: '' WindowName: ''
- ClassName: 'SysListView32' WindowName: ''
- ClassName: '#32770' WindowName: ''