Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'shell' = 'Explorer.exe %WINDIR%\fonts\Rundll32.exe'
- %WINDIR%\Fonts\Rundll32.exe
- %WINDIR%\msagent\agentsvr.exe -Embedding
- %WINDIR%\Fonts\I386.INI
- %WINDIR%\Fonts\NAME.INI
- %WINDIR%\Fonts\MIRC.INI
- %WINDIR%\Fonts\wins.ini
- %WINDIR%\Fonts\script.dll
- %WINDIR%\Fonts\TOTE.INI
- %WINDIR%\Fonts\Rundll32.exe
- %WINDIR%\Fonts\WINNIK.INI
- %WINDIR%\Fonts\driver.dll
- %WINDIR%\Fonts\verdana.ico
- %WINDIR%\Fonts\control.ini
- %WINDIR%\Fonts\verdana.ico
- %WINDIR%\Fonts\script.dll
- %WINDIR%\Fonts\control.ini
- %WINDIR%\Fonts\WINNIK.INI
- %WINDIR%\Fonts\driver.dll
- 'ir#.##dernet.org':6667
- 'ta###.##.us.undernet.org':6667
- DNS ASK ir#.##dernet.org
- DNS ASK ta###.##.us.undernet.org
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''