Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'wuauclt' = '<DRIVERS>\start.bat'
- '<DRIVERS>\IEXPLORE.exe'
- '<DRIVERS>\EXPLORER.exe'
- '<DRIVERS>\SVCHOST.exe'
- '%WINDIR%\regedit.exe' /S mech.reg
- '<SYSTEM32>\cmd.exe' /c ""<DRIVERS>\first.bat" "
- <DRIVERS>\randfiles\randaway.e
- <DRIVERS>\randfiles\randinsult.e
- <DRIVERS>\randfiles\randkicks.e
- <DRIVERS>\start.bat
- <DRIVERS>\SVCHOST.exe
- <DRIVERS>\TODO
- <DRIVERS>\randfiles\randsignoff.e
- <DRIVERS>\randfiles\randversions.e
- <DRIVERS>\mech.pid
- <DRIVERS>\randfiles\randnicks.e
- <DRIVERS>\randfiles\randpickup.e
- <DRIVERS>\randfiles\randsay.e
- <DRIVERS>\README
- <DRIVERS>\emech.sys
- <DRIVERS>\EXPLORER.exe
- <DRIVERS>\first.bat
- <DRIVERS>\VERSIONS
- <DRIVERS>\COPYING
- <DRIVERS>\cygwin1.dll
- <DRIVERS>\mech.set
- <DRIVERS>\mech.help
- <DRIVERS>\mech.levels
- <DRIVERS>\IEXPLORE.exe
- <DRIVERS>\manga-icone-005.ico
- <DRIVERS>\mech.reg
- <DRIVERS>\mech.reg
- 'localhost':1056
- 'localhost':1054
- 'localhost':1060
- 'localhost':1058
- 'us.##dernet.org':6667
- 'localhost':1042
- 'lo#######s.ca.us.undernet.org':6667
- 'localhost':1049
- 'localhost':1046
- DNS ASK us.##dernet.org
- DNS ASK up####.energymech.net
- DNS ASK Lo#######s.CA.US.Undernet.Org
- 'up####.energymech.net':9969
- ClassName: 'RegEdit_RegEdit' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'