Техническая информация
- '%TEMP%\1.tmp\HoboCopy.exe' "%HOMEPATH%"\Local Settings\Temp\ "%HOMEPATH%"\Desktop\Saved-VC-Vids\ fla*.tmp
- '<SYSTEM32>\dllhost.exe' /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
- '<SYSTEM32>\msdtc.exe'
- '<SYSTEM32>\dllhost.exe' /Processid:{D7BA884D-10F4-4D2C-AC14-F944AE1B33CB}
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\RUN ME! VC Flash Save As.bat" <Текущая директория>\"
- '<SYSTEM32>\vssvc.exe'
- %WINDIR%\repair\Backup\ServiceState\EventLogs\AppEvent.Evt
- %WINDIR%\repair\Backup\ServiceState\ConfigDirectory\userdiff
- %WINDIR%\repair\Backup\ServiceState\EventLogs\SysEvent.Evt
- %WINDIR%\repair\Backup\ServiceState\EventLogs\SecEvent.Evt
- %WINDIR%\repair\Backup\ServiceState\ConfigDirectory\TempKey.LOG
- %TEMP%\1.tmp\HoboCopy.exe
- %TEMP%\1.tmp\RUN ME! VC Flash Save As.bat
- %WINDIR%\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{49D082ED-9BD3-4600-84D7-A691A6169DAC}.crmlog
- %TEMP%\1.tmp\HoboCopy.pdb
- %WINDIR%\repair\Backup\ServiceState\ConfigDirectory\userdiff.LOG
- %WINDIR%\repair\Backup\ServiceState\ConfigDirectory\userdiff
- %TEMP%\1.tmp\HoboCopy.exe
- %TEMP%\1.tmp\RUN ME! VC Flash Save As.bat
- %TEMP%\1.tmp\HoboCopy.pdb
- %WINDIR%\repair\Backup\ServiceState\ConfigDirectory\TempKey.LOG
- %WINDIR%\Registration\R000000000007.clb
- %WINDIR%\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{BF4C4D5C-6924-41E8-9BF1-DCC37DF6F31D}.crmlog
- %WINDIR%\repair\Backup\ServiceState\EventLogs\AppEvent.Evt
- %WINDIR%\repair\Backup\ServiceState\EventLogs\SysEvent.Evt
- %WINDIR%\repair\Backup\ServiceState\EventLogs\SecEvent.Evt