Техническая информация
- '<SYSTEM32>\taskkill.exe' /F /IM AbLauncher.exe
- %TEMP%\rarsfx0\crack\readme !!!!.txt
- %TEMP%\rarsfx0\silent.cmd
- %TEMP%\rarsfx0\schirmfotosetup.exe
- %TEMP%\rarsfx0\crack\abcommons.dll
- %TEMP%\rarsfx0\programs.url
- %TEMP%\is-c6ra2.tmp\schirmfotosetup.tmp
- %TEMP%\is-7t2av.tmp\_isetup\_setup64.tmp
- %TEMP%\is-7t2av.tmp\closeapp.exe
- %TEMP%\is-7t2av.tmp\tos_install_en.rtf
- %TEMP%\is-7t2av.tmp\abelssoft_offer_screen_700x300.bmp
- 'go.##elssoft.de':443
- 'go.##elssoft.de':443
- DNS ASK go.##elssoft.de
- ClassName: 'Edit' WindowName: ''
- ClassName: '' WindowName: ''
- '%TEMP%\rarsfx0\schirmfotosetup.exe' /silent
- '%TEMP%\is-c6ra2.tmp\schirmfotosetup.tmp' /SL5="$1025C,13068233,940544,%TEMP%\RarSFX0\schirmfotosetup.exe" /silent
- '%TEMP%\is-7t2av.tmp\closeapp.exe' Schirmfoto
- '%TEMP%\is-7t2av.tmp\closeapp.exe' CaptureAndTray
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\RarSFX0\Silent.cmd" " (со скрытым окном)