Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{Q06P153G-6YN6-P2KB-711T-E5VVE8T7J4UR}] 'StubPath' = 'C:\Documents and Settings\Moad\Desktop\install\server.exe Restart'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'Policies' = ''
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'Policies' = ''
- %TEMP%\server.exe
- %TEMP%\server.sfx.exe -pmoadmed4 -d%HOMEPATH%\Local Settings\Temp
- <SYSTEM32>\cmd.exe /c ""%TEMP%\run.bat" "
- %APPDATA%\88E6680F\ak.tmp
- %TEMP%\%USERNAME%2.txt
- %TEMP%\%USERNAME%8
- %TEMP%\%USERNAME%7
- %TEMP%\server.sfx.exe
- %TEMP%\run.bat
- C:\Documents and Settings\Moad\Desktop\install\server.exe
- %TEMP%\server.exe
- %TEMP%\%USERNAME%8
- %TEMP%\%USERNAME%7
- %TEMP%\%USERNAME%2.txt
- 'gl####ed.no-ip.org':288
- DNS ASK gl####ed.no-ip.org
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''