Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{8EJQ2B50-QLY1-H812-84RA-Q4Q4ID154O30}] 'StubPath' = ''
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'winxp' = ''
- '%WINDIR%\winxp.exe'
- '%TEMP%\RarSFX1\server.exe'
- '%TEMP%\RarSFX0\server.sfx.exe' -p123 -%HOMEPATH%\Local Settings\Temp
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\RarSFX0\dl.bat" "
- %APPDATA%\Microsoft\Windows\L5WGa94D.cfg
- %WINDIR%\winxp.exe
- %APPDATA%\Microsoft\Windows\L5WGa94D.dat
- %TEMP%\RarSFX0\dl.bat
- %TEMP%\RarSFX0\server.sfx.exe
- %TEMP%\RarSFX1\server.exe
- %APPDATA%\Microsoft\Windows\L5WGa94D.dat
- %APPDATA%\Microsoft\Windows\L5WGa94D.cfg
- 'de####sa.zapto.org':5002
- 'localhost':1037
- DNS ASK de####sa.zapto.org
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''