Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\auto_gas] 'Start' = '00000002'
- <SYSTEM32>\devcon.exe disable @ROOT\LEGACY_GBPKM\0000
- <SYSTEM32>\snetcfg.exe -v -u nt_ndisrd
- <SYSTEM32>\gb_service.exe
- %WINDIR%\Temp\fiphmfa
- C:\SessionChange_06.05.2012 _ 02.42.38.log
- %WINDIR%\Temp\autA.tmp
- %WINDIR%\Temp\aut9.tmp
- %TEMP%\aut8.tmp
- <SYSTEM32>\registro_driver.reg
- <SYSTEM32>\gb_service.exe
- %WINDIR%\Temp\autF.tmp
- %WINDIR%\Temp\aut10.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\painel[1]
- %WINDIR%\Temp\autE.tmp
- %WINDIR%\Temp\autB.tmp
- %WINDIR%\Temp\autC.tmp
- %WINDIR%\Temp\autD.tmp
- <SYSTEM32>\registro_bb.reg
- <SYSTEM32>\devcon.exe
- %TEMP%\aut3.tmp
- <SYSTEM32>\gb_catchme.exe
- %TEMP%\aut2.tmp
- %TEMP%\aut1.tmp
- %TEMP%\zgermjw
- C:\SessionChange_06.05.2012 _ 02.42.29.log
- %TEMP%\aut6.tmp
- <SYSTEM32>\registro_sicredi.reg
- %TEMP%\aut7.tmp
- <SYSTEM32>\registro_itau.reg
- %TEMP%\aut4.tmp
- <SYSTEM32>\snetcfg.exe
- %TEMP%\aut5.tmp
- %WINDIR%\Temp\autA.tmp
- %WINDIR%\Temp\autB.tmp
- %WINDIR%\Temp\aut9.tmp
- %WINDIR%\Temp\fiphmfa
- %WINDIR%\Temp\autC.tmp
- %WINDIR%\Temp\autF.tmp
- %WINDIR%\Temp\aut10.tmp
- %WINDIR%\Temp\autD.tmp
- %WINDIR%\Temp\autE.tmp
- %TEMP%\aut2.tmp
- %TEMP%\aut3.tmp
- %TEMP%\aut1.tmp
- %TEMP%\zgermjw
- %TEMP%\aut4.tmp
- %TEMP%\aut7.tmp
- %TEMP%\aut8.tmp
- %TEMP%\aut5.tmp
- %TEMP%\aut6.tmp
- '20#.#15.228.178':80
- 20#.#15.228.178/painel/?ad###################################
- ClassName: 'Shell_TrayWnd' WindowName: ''