Техническая информация
- %TEMP%\1.tmp\12.exe /stext test.txt
- %TEMP%\1.tmp\HollowF.exe
- %TEMP%\compile.exe
- %TEMP%\чистит_реестр_от_вх.и_се.exe
- <SYSTEM32>\cmd.exe /c ""%TEMP%\1.tmp\compile.bat" "
- [<HKLM>\SOFTWARE\FlashFXP]
- [<HKLM>\Software\Ghisler\Total Commander]
- [<HKCU>\Software\Ghisler\Total Commander]
- [<HKCU>\Software\Far\Plugins\FTP\Hosts]
- [<HKCU>\Software\Far2\Plugins\FTP\Hosts]
- [<HKCU>\Software\Google\Google Talk\Accounts]
- <SYSTEM32>\d3d9caps.dat
- %TEMP%\1.tmp\12.exe
- %TEMP%\NO_PWDS_report_14-11-2011_12-32-50-FCMI.bin
- %TEMP%\1.tmp\test.txt
- <Текущая директория>\ufr_files\NO_PWDS_report_14-11-2011_12-32-50-FCMI.bin
- %TEMP%\чистит_реестр_от_вх.и_се.exe
- %TEMP%\compile.exe
- %TEMP%\report_14-11-2011_12-32-50-FCMI.bin
- %TEMP%\1.tmp\HollowF.exe
- %TEMP%\1.tmp\compile.bat
- %TEMP%\1.tmp\12.exe
- %TEMP%\1.tmp\compile.bat
- %TEMP%\NO_PWDS_report_14-11-2011_12-32-50-FCMI.bin
- %TEMP%\1.tmp\HollowF.exe
- '93.##8.134.11':25
- DNS ASK sm##.yandex.ru
- '<IP-адрес в локальной сети>':1037
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'SysListView32' WindowName: ''