Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'f3fef00b2f633e0ad74deee2c8d77475' = '"%WINDIR%\SysWOW64\system.exe" ..'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'f3fef00b2f633e0ad74deee2c8d77475' = '"%WINDIR%\SysWOW64\system.exe" ..'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%WINDIR%\SysWOW64\system.exe" "system.exe" ENABLE
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\4.tmp
- %TEMP%\$inst\temp_0.tmp
- %WINDIR%\syswow64\system.exe
- %ProgramFiles(x86)%\startorbz studio\diablestarttips.reg
- %ProgramFiles(x86)%\startorbz studio\enablestarttips.reg
- %ProgramFiles(x86)%\startorbz studio\readme.txt
- %ProgramFiles(x86)%\startorbz studio\startorbz studio 2.1.exe
- %ProgramFiles(x86)%\startorbz studio\startorbz studio 3.1a.exe
- %ProgramFiles(x86)%\startorbz studio\vicioushelp.dll
- %ProgramFiles(x86)%\%startorbz studio%\startorbz studio\uninstall.exe
- %HOMEPATH%\desktop\startorbz studio.lnk
- %ProgramFiles(x86)%\%startorbz studio%\startorbz studio\uninstall.ini
- %TEMP%\$inst\temp_0.tmp
- 'zz####eryy.ddns.net':5552
- DNS ASK zz####eryy.ddns.net
- '%WINDIR%\syswow64\system.exe'
- '%WINDIR%\syswow64\system.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%WINDIR%\SysWOW64\system.exe" "system.exe" ENABLE' (со скрытым окном)