Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Debugwdw] 'Start' = '00000002'
- %WINDIR%\irisenglne.exe
- <SYSTEM32>\svchost.exe -k netsvcs
- iexplore.exe
- %PROGRAM_FILES%\wi134406nd.temp
- %WINDIR%\MySomeInfo.ini
- <Текущая директория>\irisengine.exe
- %WINDIR%\HowArMe.reg
- %WINDIR%\HowArMe.txt
- %TEMP%\~imsinst.tmp
- %TEMP%\~imsinst.exe
- %TEMP%\irisengine.exe
- %PROGRAM_FILES%\wi131250nd.temp
- %WINDIR%\irisenglne.exe
- %WINDIR%\MySomeInfo.ini
- <SYSTEM32>\151296.bak
- %WINDIR%\irisenglne.exe
- %WINDIR%\HowArMe.reg
- %TEMP%\~imsinst.tmp
- %TEMP%\irisengine.exe
- %WINDIR%\HowArMe.txt
- 'zm##.wowip.kr':9201
- DNS ASK zm##.wowip.kr
- ClassName: 'Shell_TrayWnd' WindowName: ''