Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices] 'Mircosoft Windows Development Environment' = 'devenv.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Mircosoft Windows Development Environment' = 'devenv.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'wextract_cleanup0' = 'rundll32.exe <SYSTEM32>\advpack.dll,DelNodeRunDLL32 "%TEMP%\IXP000.TMP\"'
- '%TEMP%\IXP000.TMP\LIMEWI~1.EXE'
- '<SYSTEM32>\devenv.exe' 464 "%TEMP%\IXP000.TMP\rundll32.exe"
- '%TEMP%\IXP000.TMP\rundll32.exe'
- ClassName: 'PROCMON_WINDOW_CLASS' WindowName: '(null)'
- ClassName: 'RegMonClass' WindowName: '(null)'
- ClassName: 'FileMonClass' WindowName: '(null)'
- %TEMP%\nso2.tmp
- %TEMP%\nso3.tmp\LangDLL.dll
- <SYSTEM32>\devenv.exe
- %TEMP%\IXP000.TMP\rundll32.exe
- %ALLUSERSPROFILE%\Application Data\TEMP:41FA22AC
- <SYSTEM32>\devenv.exe
- %TEMP%\IXP000.TMP\rundll32.exe
- '64.#6.64.41':7777
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'ThunderRT6FormDC' WindowName: '(null)'
- ClassName: 'ThunderRT6FormDC' WindowName: 'Shareware Cheater v 3.0'