Техническая информация
- %WINDIR%\f2256.reg
- %WINDIR%\infosapi.dll
- %ProgramFiles(x86)%\messenger\acpi.vxd
- %WINDIR%\system\<Имя файла>.exe
- %ProgramFiles(x86)%\messenger\sqm.tmp
- %WINDIR%\f2256.reg
- %ProgramFiles(x86)%\messenger\acpi.vxd
- %ProgramFiles(x86)%\messenger\sqm.tmp
- %WINDIR%\f2256.reg
- %ProgramFiles(x86)%\messenger\acpi.vxd
- %ProgramFiles(x86)%\messenger\sqm.tmp
- 'au######amostudo.kit.net':80
- http://www.au######amostudo.kit.net/nnn/images.zip
- DNS ASK au######amostudo.kit.net
- ClassName: 'DDAE' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- '%WINDIR%\syswow64\regedit.exe' /s %WINDIR%\F2256Reg' (со скрытым окном)
- '%WINDIR%\syswow64\regedit.exe' /s %WINDIR%\F2256Reg