Техническая информация
- <SYSTEM32>\tasks\parkcontrol
- %TEMP%\rarsfx0\parkcontrol.exe
- %TEMP%\rarsfx0\pl_rsrc_korean.dll
- %TEMP%\rarsfx0\pl_rsrc_temp.dll
- %TEMP%\rarsfx0\pl_rsrc_spanish.dll
- %TEMP%\rarsfx0\pl_rsrc_russian.dll
- %TEMP%\rarsfx0\pl_rsrc_ptbr.dll
- %TEMP%\rarsfx0\pl_rsrc_polish.dll
- %TEMP%\rarsfx0\pl_rsrc_slovenian.dll
- %TEMP%\rarsfx0\pl_rsrc_japanese.dll
- %TEMP%\rarsfx0\pl_rsrc_german.dll
- %TEMP%\rarsfx0\pl_rsrc_french.dll
- %TEMP%\rarsfx0\pl_rsrc_finnish.dll
- %TEMP%\rarsfx0\pl_rsrc_english.dll
- %TEMP%\rarsfx0\pl_rsrc_chinese_traditional.dll
- %TEMP%\rarsfx0\pl_rsrc_chinese.dll
- %TEMP%\rarsfx0\pl_rsrc_italian.dll
- %TEMP%\rarsfx0\pl_rsrc_bulgarian.dll
- 'up####.bitsum.com':443
- 'microsoft.com':80
- 'oc##.thawte.com':80
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- http://oc##.thawte.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD%2Fyl6nWPkczAQUe1tFz6%2FOy3r9MZIaarbzRutXSFACEEeXTXhzpbyrDS%2BzcBkvzl4%3D
- 'up####.bitsum.com':443
- DNS ASK up####.bitsum.com
- DNS ASK microsoft.com
- DNS ASK oc##.thawte.com
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'WndClass-{df0cc042-6f6f-4712-bf25-2b984f3e8777}' WindowName: 'WndName-{7298c6b8-835f-4234-8054-49925ccd4038}'
- '%TEMP%\rarsfx0\parkcontrol.exe'