Техническая информация
- <SYSTEM32>\logonui.exe /status /shutdown
- %WINDIR%\regedit.exe /s "%HOMEPATH%\My Documents\IntMayak\Temp.reg"
- %WINDIR%\Explorer.EXE
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\89ABCDEF\desktop.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\C0P8UABP\desktop.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\9QSBATF4\desktop.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\GHIJKL45\desktop.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini
- %HOMEPATH%\My Documents\IntMayak\Temp.reg
- %HOMEPATH%\My Documents\IntMayak\0102.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\desktop.ini
- <SYSTEM32>\oisrwic.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\GHIJKL45\desktop.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\9QSBATF4\desktop.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\C0P8UABP\desktop.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\89ABCDEF\desktop.ini
- %HOMEPATH%\My Documents\IntMayak\0102.tmp
- %HOMEPATH%\My Documents\IntMayak\Temp.reg
- 'te###consta.com':80
- te###consta.com/phpbb/slog.php?in#####################
- DNS ASK te###consta.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'StatusWindowClass' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''