Техническая информация
- Редактора реестра (RegEdit)
- '<SYSTEM32>\taskkill.exe' /IM regedit.exe /F
- '<SYSTEM32>\taskkill.exe' /IM taskmgr.exe /F
- %TEMP%\provegay.exe
- %TEMP%\mems 3.0 sources\ncur_combo_killer\project1.cfg
- %TEMP%\mems 3.0 sources\ncur_combo_killer\project1.dof
- %TEMP%\mems 3.0 sources\ncur_combo_killer\project1.dpr
- %TEMP%\mems 3.0 sources\ncur_combo_killer\project1.res
- %TEMP%\mems 3.0 sources\ncur_combo_killer\unit1.dcu
- %TEMP%\mems 3.0 sources\ncur_combo_killer\unit1.ddp
- %TEMP%\mems 3.0 sources\ncur_combo_killer\unit1.dfm
- %TEMP%\mems 3.0 sources\ncur_combo_killer\unit1.pas
- %TEMP%\mems 3.0 sources\provegay\fxnyit1rtzmsffknxn4c05rjo__lpezpw7wjdan4vglez89o67mooxj2isplpy5w_qqaiizpt3fgc9umm3gmqxzp.ico
- %TEMP%\mems 3.0 sources\provegay\project1.cfg
- %TEMP%\mems 3.0 sources\provegay\project1.dpr
- %TEMP%\mems 3.0 sources\provegay\гей\f4.jpg
- %TEMP%\mems 3.0 sources\provegay\project1.res
- %TEMP%\mems 3.0 sources\provegay\unit1.dcu
- %TEMP%\mems 3.0 sources\provegay\unit1.ddp
- %TEMP%\mems 3.0 sources\provegay\unit1.dfm
- %TEMP%\mems 3.0 sources\provegay\unit1.pas
- %TEMP%\mems 3.0 sources\provegay\гей\f0.jpg
- %TEMP%\mems 3.0 sources\provegay\гей\f1.jpg
- %TEMP%\mems 3.0 sources\provegay\гей\f10.jpg
- %TEMP%\mems 3.0 sources\provegay\гей\f2.jpg
- %TEMP%\mems 3.0 sources\provegay\гей\f3.jpg
- %TEMP%\mems 3.0 sources\ncurp.txt
- %TEMP%\mems 3.0 sources\provegay\project1.dof
- %TEMP%\mems 3.0 sources\ncurl.txt
- %TEMP%\mems 3.0 sources\menubard\unit1.ddp
- %TEMP%\mems 3.0 sources\menubar\unit1.dcu
- %TEMP%\mems 3.0 sources\menubar\unit1.ddp
- %TEMP%\mems 3.0 sources\menubar\unit1.dfm
- %TEMP%\mems 3.0 sources\menubar\unit1.pas
- %TEMP%\mems 3.0 sources\menubar\папн1пп2.jpg
- %TEMP%\mems 3.0 sources\menubard\project1.cfg
- %TEMP%\mems 3.0 sources\menubard\project1.dof
- %TEMP%\mems 3.0 sources\menubard\project1.dpr
- %TEMP%\mems 3.0 sources\menubard\project1.res
- %TEMP%\mems 3.0 sources\menubard\unit1.dcu
- %TEMP%\mems 3.0 sources\menubard\unit1.dfm
- %TEMP%\mems 3.0 sources\moaning_scumbag\unit1.pas
- %TEMP%\mems 3.0 sources\menubard\unit1.pas
- %TEMP%\mems 3.0 sources\moaning_scumbag\#22.ico
- %TEMP%\mems 3.0 sources\moaning_scumbag\0c276ac3efd3ee35e9257ca6a8na--materialy-dlya-tvorchestva-steganaya-sinyaya-zigzag-art-89p10.jpg
- %TEMP%\mems 3.0 sources\moaning_scumbag\project1.cfg
- %TEMP%\mems 3.0 sources\moaning_scumbag\project1.dof
- %TEMP%\mems 3.0 sources\moaning_scumbag\project1.dpr
- %TEMP%\mems 3.0 sources\moaning_scumbag\project1.res
- %TEMP%\mems 3.0 sources\moaning_scumbag\unit1.dcu
- %TEMP%\mems 3.0 sources\moaning_scumbag\unit1.ddp
- %TEMP%\mems 3.0 sources\moaning_scumbag\unit1.dfm
- %TEMP%\mems 3.0 sources\mouses.txt
- %TEMP%\mems 3.0 sources\provegay\гей\f5.jpg
- %TEMP%\mems 3.0 sources\provegay\гей\f6.jpg
- %TEMP%\mems 3.0 sources\provegay\гей\f7.jpg
- %TEMP%\mems 3.0 sources\skalasms\oboi_yst.dfm
- %TEMP%\mems 3.0 sources\skalasms\oboi_yst.pas
- %TEMP%\mems 3.0 sources\skalasms\project1.cfg
- %TEMP%\mems 3.0 sources\skalasms\project1.dof
- %TEMP%\mems 3.0 sources\skalasms\project1.dpr
- %TEMP%\mems 3.0 sources\skalasms\project1.res
- %TEMP%\mems 3.0 sources\skalasms\unit1.dcu
- %TEMP%\mems 3.0 sources\skalasms_1\oboi_yst.dcu
- %TEMP%\mems 3.0 sources\skalasms_1\oboi_yst.ddp
- %TEMP%\mems 3.0 sources\skalasms\oboi_yst.dcu
- %TEMP%\mems 3.0 sources\skalasms\oboi_yst.ddp
- %TEMP%\mems 3.0 sources\skalasms_1\oboi_yst.dfm
- %TEMP%\mems 3.0 sources\skalasms_1\project1.dof
- %TEMP%\mems 3.0 sources\skalasms_1\project1.dpr
- %TEMP%\mems 3.0 sources\skalasms_1\project1.res
- %TEMP%\mems 3.0 sources\skalasms_1\unit1.dcu
- %TEMP%\mems 3.0 sources\skalasms_p.txt
- %TEMP%\mems 3.0 sources\textnew.txt
- %TEMP%\mems 3.0 sources\tunnel.txt
- %TEMP%\mems 3.0 sources\zebra207.txt
- %TEMP%\mems 3.0 sources\zhdun.txt
- %TEMP%\mems 3.0 sources\skalasms_1\oboi_yst.pas
- %TEMP%\mems 3.0 sources\skalasms_1\project1.cfg
- %TEMP%\mems 3.0 sources\skaladesktop.txt
- %TEMP%\mems 3.0 sources\sexmanager\sexmaganer.pas
- %TEMP%\mems 3.0 sources\sexmanager\sexmaganer.dfm
- %TEMP%\mems 3.0 sources\provegay\гей\f9.jpg
- %TEMP%\mems 3.0 sources\provegay\гей\r_гей.jpg
- %TEMP%\mems 3.0 sources\provegay\гей\r_натурал.jpg
- %TEMP%\mems 3.0 sources\pyk_copy\project1.cfg
- %TEMP%\mems 3.0 sources\pyk_copy\project1.dof
- %TEMP%\mems 3.0 sources\pyk_copy\project1.dpr
- %TEMP%\mems 3.0 sources\pyk_copy\project1.res
- %TEMP%\mems 3.0 sources\pyk_copy\unit1.dcu
- %TEMP%\mems 3.0 sources\pyk_copy\unit1.ddp
- %TEMP%\mems 3.0 sources\pyk_copy\unit1.dfm
- %TEMP%\mems 3.0 sources\provegay\гей\f8.jpg
- %TEMP%\mems 3.0 sources\pyk_copy\unit1.pas
- %TEMP%\mems 3.0 sources\sexmanager\128.ico
- %TEMP%\mems 3.0 sources\sexmanager\128.png
- %TEMP%\mems 3.0 sources\sexmanager\67356783_3.jpg
- %TEMP%\mems 3.0 sources\sexmanager\desktop.ini
- %TEMP%\mems 3.0 sources\sexmanager\project1.cfg
- %TEMP%\mems 3.0 sources\sexmanager\project1.dof
- %TEMP%\mems 3.0 sources\sexmanager\project1.dpr
- %TEMP%\mems 3.0 sources\sexmanager\project1.res
- %TEMP%\mems 3.0 sources\sexmanager\sexmaganer.dcu
- %TEMP%\mems 3.0 sources\sexmanager\sexmaganer.ddp
- %TEMP%\mems 3.0 sources\requests.txt
- %TEMP%\mems 3.0 sources\menubar\project1.res
- C:\virusnew17\pyk.wav
- %TEMP%\mems 3.0 sources\menubar\project1.dpr
- %TEMP%\mems 3.0 sources\menubar\project1.cfg
- %TEMP%\q3f.wav
- %TEMP%\q9.wav
- %TEMP%\q10.wav
- %TEMP%\q11.wav
- %TEMP%\q12.wav
- %TEMP%\q13.wav
- %TEMP%\q14.wav
- %TEMP%\q15.wav
- %TEMP%\sexmanager.exe
- %TEMP%\skalasms.exe
- %TEMP%\skalasms_p.exe
- %TEMP%\benbros.wav
- %TEMP%\taco_bell.wav
- %TEMP%\textnew.exe
- %TEMP%\track.wav
- %TEMP%\4_sek_mems_3.0_sounds.exe
- %TEMP%\ah1.wav
- %TEMP%\ah2.wav
- %TEMP%\ah3.wav
- %TEMP%\bababoy.wav
- %TEMP%\ban.wav
- %TEMP%\ben.wav
- %TEMP%\q3.wav
- %TEMP%\skalasms_1.exe
- %TEMP%\q2.wav
- %TEMP%\mouses.exe
- %TEMP%\pyk_copy.exe
- %TEMP%\aop.exe
- %TEMP%\aops.exe
- %TEMP%\colors_and_invers.exe
- %TEMP%\cursormol4it.exe
- %TEMP%\curworkstas.exe
- %TEMP%\menubar.exe
- %TEMP%\menubard.exe
- %TEMP%\moaning_scumbag.exe
- %TEMP%\morg2.exe
- %TEMP%\ncur_combo_killer.exe
- %TEMP%\pyk.wav
- %TEMP%\ncurl.exe
- %TEMP%\benr2.wav
- %TEMP%\benr3.wav
- %TEMP%\benr4.wav
- %TEMP%\bensos.wav
- %TEMP%\bensospivas.wav
- %TEMP%\benyes.wav
- %TEMP%\bruh.wav
- %TEMP%\msvcp100d.dll
- %TEMP%\msvcr100d.dll
- %TEMP%\q1.wav
- %TEMP%\benfyy.wav
- %TEMP%\benhohoho.wav
- %TEMP%\benklad.wav
- %TEMP%\meme 4.jpg
- %TEMP%\.bat
- %TEMP%\razmnoshenuya.bat
- %TEMP%\runwithadminrights.vbs
- %TEMP%\mems 3.0 sources\4_sek_mems_3.0_sounds.txt
- %TEMP%\mems 3.0 sources\aop(s).txt
- %TEMP%\mems 3.0 sources\colors_and_invers.txt
- %TEMP%\mems 3.0 sources\cursormol4it.txt
- %TEMP%\mems 3.0 sources\curworkstas.txt
- %TEMP%\meme 2.jpg
- %TEMP%\meme 3.jpg
- %TEMP%\mems 3.0 sources\mems sms\anonymous_mask_png13.ico
- %TEMP%\mems 3.0 sources\mems sms\oboi_yst.dfm
- %TEMP%\mems 3.0 sources\mems sms\oboi_yst.pas
- %TEMP%\mems 3.0 sources\mems sms\project1.cfg
- %TEMP%\mems 3.0 sources\mems sms\project1.dof
- %TEMP%\mems 3.0 sources\mems sms\project1.dpr
- %TEMP%\mems 3.0 sources\mems sms\project1.res
- %TEMP%\mems 3.0 sources\mems sms\unit1.dcu
- %TEMP%\mems 3.0 sources\mems_3.0_sounds.txt
- %TEMP%\mems 3.0 sources\mems_3.0_work.txt
- %TEMP%\mems 3.0 sources\mems sms\oboi_yst.dcu
- %TEMP%\mems 3.0 sources\mems sms\oboi_yst.ddp
- %TEMP%\meme 1.jpg
- %TEMP%\meme7.jpg
- %TEMP%\meme 20.png
- %TEMP%\benno.wav
- %TEMP%\benpivas.wav
- %TEMP%\benpivasbros.wav
- %TEMP%\benpos.wav
- %TEMP%\benr1.wav
- %TEMP%\mems_3.0_work.exe
- %TEMP%\reboot.bat
- %TEMP%\meme 5.jpg
- %TEMP%\meme 6.jpg
- %TEMP%\meme 7.jpg
- %TEMP%\benkxyy.wav
- %TEMP%\meme 8.png
- %TEMP%\meme 10.jpg
- %TEMP%\meme 11.png
- %TEMP%\meme 12.jpg
- %TEMP%\meme 13.jpg
- %TEMP%\meme 14.jpg
- %TEMP%\meme 15.jpg
- %TEMP%\meme 16.jpg
- %TEMP%\meme 17.jpg
- %TEMP%\meme 18.jpg
- %TEMP%\meme 19.jpg
- %TEMP%\meme 9.jpg
- %TEMP%\mems 3.0 sources\menubar\project1.dof
- nul
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: '' WindowName: ''
- '%TEMP%\mems_3.0_work.exe'
- '%TEMP%\pyk_copy.exe'
- '<SYSTEM32>\wscript.exe' "%TEMP%\RunWithAdminRights.vbs"
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Reboot.bat" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\razmnoshenuya.bat" "
- '<SYSTEM32>\reg.exe' add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v "DisableRegistryTools" /t REG_DWORD /d 1 /f
- '<SYSTEM32>\shutdown.exe' -r -f -t 15
- '<SYSTEM32>\cmd.exe' /c C:\Path\To\YourScript.bat
- '<SYSTEM32>\reg.exe' add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v "DisableTaskMgr" /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "DisableSafeMode" /t REG_DWORD /d 1 /f