Техническая информация
- <SYSTEM32>\rundll32.exe <SYSTEM32>\netplwiz.dll,AddNetPlaceRunDll
- <SYSTEM32>\rundll32.exe <SYSTEM32>\hnetwiz.dll,HomeNetWizardRunDll
- <SYSTEM32>\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {601ac3dc-786a-4eb0-bf40-ee3521e70bfb} -Embedding
- %WINDIR%\srchasst\mui\0409\lclsrch.xml.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\balloon[1].xsl
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\lclsrch[1].xml
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\balloon[1].xsl
- %WINDIR%\srchasst\mui\0409\balloon.xsl.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\lclsrch[1].xml
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\balloon[1].xsl
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\lclsrch[1].xml
- %WINDIR%\srchasst\mui\0409\balloon.xsl.tmp
- %WINDIR%\srchasst\mui\0409\lclsrch.xml.tmp
- 'sa.##ndows.com':80
- sa.##ndows.com/sasearch/lclsrch.xml
- sa.##ndows.com/sasearch/balloon.xsl
- DNS ASK sa.##ndows.com
- ClassName: '' WindowName: 'GINA Logon'
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''