Техническая информация
- spy.exe
- %TEMP%\rarsfx0\system.exe
- %WINDIR%\syswow64\msstdfmt.dll
- %WINDIR%\syswow64\msdycword.dll
- %WINDIR%\syswow64\msdunkern.dll
- %WINDIR%\syswow64\ijl_11.dll
- %WINDIR%\syswow64\richtx32.ocx
- %WINDIR%\syswow64\mswyncore.dll
- %TEMP%\rarsfx0\start.bat
- %WINDIR%\syswow64\mswinsck.ocx
- %TEMP%\rarsfx0\spy.exe
- %TEMP%\rarsfx0\source\portable application.ico
- %TEMP%\rarsfx0\portable\reginfo.reg
- %TEMP%\rarsfx0\appdata\spy.exe
- %TEMP%\rarsfx0\appdata\log\visual\02112008.dat
- %TEMP%\rarsfx0\appdata\log\text\aiotxt.dat
- %TEMP%\rarsfx0\appdata\tips
- %TEMP%\rarsfx0\appdata\help.chm
- %TEMP%\rarsfx0\source\portable application.nsi
- %TEMP%\nsr1a6.tmp\registry.dll
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- '%TEMP%\rarsfx0\system.exe'
- '%TEMP%\rarsfx0\spy.exe'
- '%TEMP%\rarsfx0\appdata\spy.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\RarSFX0\start.bat" "
- '%WINDIR%\syswow64\regedit.exe' /s "%TEMP%\RarSFX0\portable\RegInfo.reg"