Техническая информация
- '%TEMP%\nsf5.tmp\ns1B.tmp' "netsh.exe" firewall delete allowedprogram "<Текущая директория>\DualDesk.exe" ALL
- '%TEMP%\nsf5.tmp\ns1A.tmp' REG.EXE DELETE "SYSTEM\CurrentControlSet\Services\DD_Service" /f
- '%TEMP%\nsf5.tmp\ns1D.tmp' REG.EXE DELETE "HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\DualDesk-Server" /f
- '%TEMP%\nsf5.tmp\ns1C.tmp' "netsh.exe" firewall delete allowedprogram "<Текущая директория>\DualDesk.exe" CURRENT
- '%TEMP%\nsf5.tmp\ns17.tmp' REG.EXE DELETE "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DD_Service" /f
- '%TEMP%\nsf5.tmp\ns16.tmp' REG.EXE DELETE "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DD_Service\Enum" /f
- '%TEMP%\nsf5.tmp\ns19.tmp' REG.EXE DELETE "SYSTEM\CurrentControlSet\Services\DD_Service\DependOnService" /f
- '%TEMP%\nsf5.tmp\ns18.tmp' REG.EXE DELETE "SYSTEM\CurrentControlSet\Services\DD_Service\Description" /f
- '%TEMP%\nsf5.tmp\ns1E.tmp' cmd.exe /C del /P /Q "%TEMP%\DD.txt"
- '%TEMP%\nsf5.tmp\ns24.tmp' cmd.exe /C RMDIR /S /Q "%TEMP%\DDTmp2"
- '%TEMP%\nsf5.tmp\ns23.tmp' cmd.exe /C RMDIR /S /Q "%TEMP%\DDTmp1"
- '%TEMP%\nsf5.tmp\ns26.tmp' cmd.exe /C RMDIR /S /Q "%HOMEPATH%\Local Settings\Temp"
- '%TEMP%\nsf5.tmp\ns25.tmp' cmd.exe /C RMDIR /S /Q "<Текущая директория>"
- '%TEMP%\nsf5.tmp\ns20.tmp' cmd.exe /C RMDIR /S /Q "%TEMP%\DDTmp2"
- '%TEMP%\nsf5.tmp\ns1F.tmp' cmd.exe /C RMDIR /S /Q "%TEMP%\DDTmp1"
- '%TEMP%\nsf5.tmp\ns22.tmp' cmd.exe /C del /P /Q "%TEMP%\DD.txt"
- '%TEMP%\nsf5.tmp\ns21.tmp' cmd.exe /C RMDIR /S /Q "%HOMEPATH%\Local Settings\Temp"
- '%TEMP%\nsf5.tmp\nsA.tmp' "sc.exe" delete DD_Service
- '%TEMP%\nsf5.tmp\ns9.tmp' "net.exe" stop DD_CAD
- '%TEMP%\nsf5.tmp\nsC.tmp' "tskill.exe" DDHelper
- '%TEMP%\nsf5.tmp\nsB.tmp' "sc.exe" delete DD_CAD
- '%TEMP%\nsf5.tmp\ns6.tmp' "sc.exe" stop DD_Service
- '%TEMP%\A~ADVANTIGu_.exe' _?=<Текущая директория>\
- '%TEMP%\nsf5.tmp\ns8.tmp' "net.exe" stop DD_Service
- '%TEMP%\nsf5.tmp\ns7.tmp' "sc.exe" stop DD_CAD
- '%TEMP%\nsf5.tmp\nsD.tmp' "taskkill.exe" /F /IM DDHelper.exe /T
- '%TEMP%\nsf5.tmp\ns13.tmp' REG.EXE DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\DDExe" /f
- '%TEMP%\nsf5.tmp\ns12.tmp' REG.EXE DELETE "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DD-ShowSuperHidden" /f
- '%TEMP%\nsf5.tmp\ns15.tmp' REG.EXE DELETE "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DD_Service\Security" /f
- '%TEMP%\nsf5.tmp\ns14.tmp' REG.EXE DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\DDHelper" /f
- '%TEMP%\nsf5.tmp\nsF.tmp' "taskkill.exe" /F /IM DualDesk.exe /T
- '%TEMP%\nsf5.tmp\nsE.tmp' "tskill.exe" DualDesk
- '%TEMP%\nsf5.tmp\ns11.tmp' REG.EXE DELETE "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DD-Hidden" /f
- '%TEMP%\nsf5.tmp\ns10.tmp' REG.EXE DELETE "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DD-HideFileExt" /f
- '<SYSTEM32>\reg.exe' DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\DDExe" /f
- '<SYSTEM32>\reg.exe' DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\DDHelper" /f
- '<SYSTEM32>\reg.exe' DELETE "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DD_Service\Security" /f
- '<SYSTEM32>\reg.exe' DELETE "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DD-HideFileExt" /f
- '<SYSTEM32>\reg.exe' DELETE "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DD-Hidden" /f
- '<SYSTEM32>\reg.exe' DELETE "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DD-ShowSuperHidden" /f
- '<SYSTEM32>\reg.exe' DELETE "SYSTEM\CurrentControlSet\Services\DD_Service\DependOnService" /f
- '<SYSTEM32>\reg.exe' DELETE "SYSTEM\CurrentControlSet\Services\DD_Service" /f
- '<SYSTEM32>\reg.exe' DELETE "HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\DualDesk-Server" /f
- '<SYSTEM32>\reg.exe' DELETE "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DD_Service\Enum" /f
- '<SYSTEM32>\reg.exe' DELETE "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DD_Service" /f
- '<SYSTEM32>\reg.exe' DELETE "SYSTEM\CurrentControlSet\Services\DD_Service\Description" /f
- '<SYSTEM32>\net1.exe' stop DD_Service
- '<SYSTEM32>\net.exe' stop DD_CAD
- '<SYSTEM32>\net1.exe' stop DD_CAD
- '<SYSTEM32>\sc.exe' stop DD_Service
- '<SYSTEM32>\sc.exe' stop DD_CAD
- '<SYSTEM32>\net.exe' stop DD_Service
- '<SYSTEM32>\taskkill.exe' /F /IM DDHelper.exe /T
- '<SYSTEM32>\tskill.exe' DualDesk
- '<SYSTEM32>\taskkill.exe' /F /IM DualDesk.exe /T
- '<SYSTEM32>\sc.exe' delete DD_Service
- '<SYSTEM32>\sc.exe' delete DD_CAD
- '<SYSTEM32>\tskill.exe' DDHelper
- %TEMP%\nsf5.tmp\ns1B.tmp
- %TEMP%\nsf5.tmp\ns1A.tmp
- %TEMP%\nsf5.tmp\ns1D.tmp
- %TEMP%\nsf5.tmp\ns1C.tmp
- %TEMP%\nsf5.tmp\ns19.tmp
- %TEMP%\nsf5.tmp\ns16.tmp
- %TEMP%\nsf5.tmp\ns15.tmp
- %TEMP%\nsf5.tmp\ns18.tmp
- %TEMP%\nsf5.tmp\ns17.tmp
- <Текущая директория>\DD.txt
- %TEMP%\nsf5.tmp\ns24.tmp
- %TEMP%\nsf5.tmp\ns23.tmp
- %TEMP%\nsf5.tmp\ns26.tmp
- %TEMP%\nsf5.tmp\ns25.tmp
- %TEMP%\nsf5.tmp\ns22.tmp
- %TEMP%\nsf5.tmp\ns1F.tmp
- %TEMP%\nsf5.tmp\ns1E.tmp
- %TEMP%\nsf5.tmp\ns21.tmp
- %TEMP%\nsf5.tmp\ns20.tmp
- %TEMP%\nsf5.tmp\ns14.tmp
- %TEMP%\nsf5.tmp\ns7.tmp
- %TEMP%\nsf5.tmp\ns6.tmp
- %TEMP%\nsf5.tmp\ns9.tmp
- %TEMP%\nsf5.tmp\ns8.tmp
- %TEMP%\nsf5.tmp\nsExec.dll
- %TEMP%\A~ADVANTIGu_.exe
- %TEMP%\nsp2.tmp
- %TEMP%\DD.txt
- %TEMP%\nsh4.tmp
- %TEMP%\nsf5.tmp\nsA.tmp
- %TEMP%\nsf5.tmp\ns11.tmp
- %TEMP%\nsf5.tmp\ns10.tmp
- %TEMP%\nsf5.tmp\ns13.tmp
- %TEMP%\nsf5.tmp\ns12.tmp
- %TEMP%\nsf5.tmp\nsF.tmp
- %TEMP%\nsf5.tmp\nsC.tmp
- %TEMP%\nsf5.tmp\nsB.tmp
- %TEMP%\nsf5.tmp\nsE.tmp
- %TEMP%\nsf5.tmp\nsD.tmp
- <Текущая директория>\DD.txt
- %TEMP%\nsf5.tmp\ns1D.tmp
- %TEMP%\nsf5.tmp\ns1E.tmp
- %TEMP%\DD.txt
- %TEMP%\nsf5.tmp\ns1C.tmp
- %TEMP%\nsf5.tmp\ns19.tmp
- %TEMP%\nsf5.tmp\ns18.tmp
- %TEMP%\nsf5.tmp\ns1B.tmp
- %TEMP%\nsf5.tmp\ns1A.tmp
- %TEMP%\nsf5.tmp\ns24.tmp
- %TEMP%\nsf5.tmp\ns23.tmp
- %TEMP%\nsf5.tmp\ns26.tmp
- %TEMP%\nsf5.tmp\ns25.tmp
- %TEMP%\nsf5.tmp\ns22.tmp
- %TEMP%\nsf5.tmp\ns20.tmp
- %TEMP%\nsf5.tmp\ns1F.tmp
- %TEMP%\nsf5.tmp\nsExec.dll
- %TEMP%\nsf5.tmp\ns21.tmp
- %TEMP%\nsf5.tmp\nsC.tmp
- %TEMP%\nsf5.tmp\nsB.tmp
- %TEMP%\nsf5.tmp\nsE.tmp
- %TEMP%\nsf5.tmp\nsD.tmp
- %TEMP%\nsf5.tmp\nsA.tmp
- %TEMP%\nsf5.tmp\ns7.tmp
- %TEMP%\nsf5.tmp\ns6.tmp
- %TEMP%\nsf5.tmp\ns9.tmp
- %TEMP%\nsf5.tmp\ns8.tmp
- %TEMP%\nsf5.tmp\ns15.tmp
- %TEMP%\nsf5.tmp\ns14.tmp
- %TEMP%\nsf5.tmp\ns17.tmp
- %TEMP%\nsf5.tmp\ns16.tmp
- %TEMP%\nsf5.tmp\ns13.tmp
- %TEMP%\nsf5.tmp\ns10.tmp
- %TEMP%\nsf5.tmp\nsF.tmp
- %TEMP%\nsf5.tmp\ns12.tmp
- %TEMP%\nsf5.tmp\ns11.tmp
- ClassName: '(null)' WindowName: '(null)'
- ClassName: 'SysListView32' WindowName: '(null)'
- ClassName: '#32770' WindowName: '(null)'