Техническая информация
- 'C:\wga\wga-fix.exe'
- 'C:\wga\MGADiag.exe'
- 'C:\wga\findkey.exe'
- 'C:\wga\wga.exe'
- 'C:\wga\Keygen.exe'
- '<SYSTEM32>\wscript.exe' "C:\wga\chgxp.vbs" B7BWC-TQFHP-WBMQ8-MJHP3-389Y3
- '<SYSTEM32>\cmd.exe' /c ""c:\wga\wga.cmd" "
- %ALLUSERSPROFILE%\Application Data\Office Genuine Advantage\data\data.dat
- %ALLUSERSPROFILE%\Application Data\Microsoft\Crypto\RSA\MachineKeys\8112ba97cd9baaf45390f9ece7e8b97b_23ef5514-3059-436f-a4a7-4cefaab20eb1
- <DRIVERS>\etc\hosts1.bak
- %ALLUSERSPROFILE%\Application Data\Windows Genuine Advantage\data\data.dat
- %ALLUSERSPROFILE%\Application Data\Microsoft\Crypto\RSA\MachineKeys\6313d2dbed171bd68c3e55bf831dae92_23ef5514-3059-436f-a4a7-4cefaab20eb1
- %ALLUSERSPROFILE%\Application Data\Microsoft\Crypto\RSA\MachineKeys\affa635ad3210f2ada9bd4450b193a20_23ef5514-3059-436f-a4a7-4cefaab20eb1
- <SYSTEM32>\Microsoft\Protect\S-1-5-18\c0c83efb-b76b-480d-a0f2-54c2fc45d168
- <SYSTEM32>\Microsoft\Protect\S-1-5-18\Preferred
- %TEMP%\nsr3.tmp\System.dll
- C:\wga\wga-fix.exe
- C:\wga\chgxp.vbs
- C:\wga\wga.cmd
- C:\wga\wga.exe
- C:\wga\MGADiag.exe
- %TEMP%\nsr2.tmp
- C:\wga\findkey.exe
- C:\wga\Keygen.exe
- C:\wga\wga-fix.exe
- C:\wga\MGADiag.exe
- C:\wga\wga.exe
- C:\wga\wga.cmd
- C:\wga\chgxp.vbs
- %TEMP%\nsr3.tmp\System.dll
- C:\wga\Keygen.exe
- C:\wga\findkey.exe
- 'localhost':443
- ClassName: 'BUTTON' WindowName: '(null)'
- ClassName: 'MS_WINHELP' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'