Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Windows_rejoice2007_45] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\SVKP] 'Start' = '00000002'
- %CommonProgramFiles%\Microsoft Shared\MSInfo\Server.exe
- <SYSTEM32>\dumprep.exe 3688 -dm 7 7 %TEMP%\WER761b.dir00\calc.exe.hdmp 16325836412027088
- <SYSTEM32>\dumprep.exe 3688 -dm 7 7 %TEMP%\WER761b.dir00\calc.exe.mdmp 16325836412027076
- <SYSTEM32>\dumprep.exe 3748 -dm 7 7 %TEMP%\WER91d0.dir00\calc.exe.mdmp 16325836412027076
- <SYSTEM32>\dumprep.exe 3812 -dm 7 7 %TEMP%\WERc815.dir00\calc.exe.mdmp 16325836412027076
- <SYSTEM32>\dumprep.exe 3748 -dm 7 7 %TEMP%\WER91d0.dir00\calc.exe.hdmp 16325836412027088
- <SYSTEM32>\dumprep.exe 3568 -dm 7 7 %TEMP%\WER0a89.dir00\calc.exe.mdmp 16325836412027076
- <SYSTEM32>\dumprep.exe 3516 -dm 7 7 %TEMP%\WERef46.dir00\calc.exe.hdmp 16325836412027088
- <SYSTEM32>\dumprep.exe 3592 -dm 7 7 %TEMP%\WER3fbe.dir00\calc.exe.mdmp 16325836412027076
- <SYSTEM32>\dumprep.exe 3592 -dm 7 7 %TEMP%\WER3fbe.dir00\calc.exe.hdmp 16325836412027088
- <SYSTEM32>\dumprep.exe 3568 -dm 7 7 %TEMP%\WER0a89.dir00\calc.exe.hdmp 16325836412027088
- <SYSTEM32>\dumprep.exe 3812 -dm 7 7 %TEMP%\WERc815.dir00\calc.exe.hdmp 16325836412027088
- <SYSTEM32>\dumprep.exe 4020 -dm 7 7 %TEMP%\WER6a54.dir00\calc.exe.mdmp 16325836412027076
- <SYSTEM32>\dumprep.exe 3968 -dm 7 7 %TEMP%\WER33ef.dir00\calc.exe.hdmp 16325836412027088
- <SYSTEM32>\dumprep.exe 4020 -dm 7 7 %TEMP%\WER6a54.dir00\calc.exe.hdmp 16325836412027088
- <SYSTEM32>\dumprep.exe 4092 -dm 7 7 %TEMP%\WERce92.dir00\calc.exe.mdmp 16325836412027076
- <SYSTEM32>\dumprep.exe 4072 -dm 7 7 %TEMP%\WER8058.dir00\calc.exe.mdmp 16325836412027076
- <SYSTEM32>\dumprep.exe 3864 -dm 7 7 %TEMP%\WERe1b5.dir00\calc.exe.hdmp 16325836412027088
- <SYSTEM32>\dumprep.exe 3864 -dm 7 7 %TEMP%\WERe1b5.dir00\calc.exe.mdmp 16325836412027076
- <SYSTEM32>\dumprep.exe 3916 -dm 7 7 %TEMP%\WER1a90.dir00\calc.exe.mdmp 16325836412027076
- <SYSTEM32>\dumprep.exe 3968 -dm 7 7 %TEMP%\WER33ef.dir00\calc.exe.mdmp 16325836412027076
- <SYSTEM32>\dumprep.exe 3916 -dm 7 7 %TEMP%\WER1a90.dir00\calc.exe.hdmp 16325836412027088
- <SYSTEM32>\dumprep.exe 3128 -dm 7 7 %TEMP%\WERea62.dir00\calc.exe.mdmp 16325836412027076
- <SYSTEM32>\dumprep.exe 3088 -dm 7 7 %TEMP%\WERaaef.dir00\calc.exe.hdmp 16325836412027088
- <SYSTEM32>\dumprep.exe 3128 -dm 7 7 %TEMP%\WERea62.dir00\calc.exe.hdmp 16325836412027088
- <SYSTEM32>\dumprep.exe 3172 -dm 7 7 %TEMP%\WERf9c8.dir00\calc.exe.hdmp 16325836412027088
- <SYSTEM32>\dumprep.exe 3172 -dm 7 7 %TEMP%\WERf9c8.dir00\calc.exe.mdmp 16325836412027076
- <SYSTEM32>\dumprep.exe 2948 -dm 7 7 %TEMP%\WER440c.dir00\calc.exe.mdmp 16325836412027076
- <SYSTEM32>\calc.exe
- <SYSTEM32>\dumprep.exe 2948 -dm 7 7 %TEMP%\WER440c.dir00\calc.exe.hdmp 16325836412027096
- <SYSTEM32>\dumprep.exe 3088 -dm 7 7 %TEMP%\WERaaef.dir00\calc.exe.mdmp 16325836412027076
- <SYSTEM32>\rundll32.exe <SYSTEM32>\sysdm.cpl,NoExecuteProcessException <SYSTEM32>\calc.exe
- <SYSTEM32>\dumprep.exe 3240 -dm 7 7 %TEMP%\WER13c3.dir00\calc.exe.mdmp 16325836412027076
- <SYSTEM32>\dumprep.exe 3428 -dm 7 7 %TEMP%\WER9c75.dir00\calc.exe.hdmp 16325836412027088
- <SYSTEM32>\dumprep.exe 3428 -dm 7 7 %TEMP%\WER9c75.dir00\calc.exe.mdmp 16325836412027076
- <SYSTEM32>\dumprep.exe 3464 -dm 7 7 %TEMP%\WERced4.dir00\calc.exe.mdmp 16325836412027076
- <SYSTEM32>\dumprep.exe 3516 -dm 7 7 %TEMP%\WERef46.dir00\calc.exe.mdmp 16325836412027076
- <SYSTEM32>\dumprep.exe 3464 -dm 7 7 %TEMP%\WERced4.dir00\calc.exe.hdmp 16325836412027088
- <SYSTEM32>\dumprep.exe 3296 -dm 7 7 %TEMP%\WER5dfa.dir00\calc.exe.mdmp 16325836412027076
- <SYSTEM32>\dumprep.exe 3240 -dm 7 7 %TEMP%\WER13c3.dir00\calc.exe.hdmp 16325836412027088
- <SYSTEM32>\dumprep.exe 3296 -dm 7 7 %TEMP%\WER5dfa.dir00\calc.exe.hdmp 16325836412027088
- <SYSTEM32>\dumprep.exe 3348 -dm 7 7 %TEMP%\WER6460.dir00\calc.exe.hdmp 16325836412027088
- <SYSTEM32>\dumprep.exe 3348 -dm 7 7 %TEMP%\WER6460.dir00\calc.exe.mdmp 16325836412027076
- <SYSTEM32>\calc.exe
- %TEMP%\WER761b.dir00\calc.exe.hdmp
- %TEMP%\WER761b.dir00\appcompat.txt
- %TEMP%\WER0a89.dir00\calc.exe.hdmp
- %TEMP%\WER761b.dir00\calc.exe.mdmp
- %TEMP%\WER761b.dir00\manifest.txt
- %TEMP%\WER91d0.dir00\appcompat.txt
- %TEMP%\WER91d0.dir00\manifest.txt
- %TEMP%\WER91d0.dir00\calc.exe.mdmp
- %TEMP%\WER91d0.dir00\calc.exe.hdmp
- %TEMP%\WERef46.dir00\calc.exe.mdmp
- %TEMP%\WERef46.dir00\calc.exe.hdmp
- %TEMP%\WERced4.dir00\appcompat.txt
- %TEMP%\WERced4.dir00\manifest.txt
- %TEMP%\WERef46.dir00\appcompat.txt
- %TEMP%\WER3fbe.dir00\calc.exe.mdmp
- %TEMP%\WER3fbe.dir00\appcompat.txt
- %TEMP%\WERef46.dir00\manifest.txt
- %TEMP%\WER0a89.dir00\calc.exe.mdmp
- %TEMP%\WER1a90.dir00\manifest.txt
- %TEMP%\WER33ef.dir00\calc.exe.mdmp
- %TEMP%\WER1a90.dir00\calc.exe.hdmp
- %TEMP%\WER1a90.dir00\appcompat.txt
- %TEMP%\WER33ef.dir00\calc.exe.hdmp
- %TEMP%\WER6a54.dir00\calc.exe.mdmp
- %TEMP%\WER6a54.dir00\calc.exe.hdmp
- %TEMP%\WER33ef.dir00\appcompat.txt
- %TEMP%\WER33ef.dir00\manifest.txt
- %TEMP%\WERc815.dir00\appcompat.txt
- %TEMP%\WERc815.dir00\manifest.txt
- %TEMP%\WERc815.dir00\calc.exe.mdmp
- %TEMP%\WERc815.dir00\calc.exe.hdmp
- %TEMP%\WERe1b5.dir00\calc.exe.mdmp
- %TEMP%\WERe1b5.dir00\manifest.txt
- %TEMP%\WER1a90.dir00\calc.exe.mdmp
- %TEMP%\WERe1b5.dir00\calc.exe.hdmp
- %TEMP%\WERe1b5.dir00\appcompat.txt
- %TEMP%\WERced4.dir00\calc.exe.hdmp
- %TEMP%\WERea62.dir00\calc.exe.mdmp
- %TEMP%\WERea62.dir00\calc.exe.hdmp
- %TEMP%\WERaaef.dir00\appcompat.txt
- %TEMP%\WERaaef.dir00\manifest.txt
- %TEMP%\WERf9c8.dir00\calc.exe.mdmp
- %TEMP%\WERea62.dir00\manifest.txt
- %TEMP%\WERf9c8.dir00\appcompat.txt
- %TEMP%\WERf9c8.dir00\calc.exe.hdmp
- %TEMP%\WERea62.dir00\appcompat.txt
- <SYSTEM32>\_Server.exe
- %TEMP%\WER440c.dir00\calc.exe.mdmp
- <SYSTEM32>\SVKP.sys
- %CommonProgramFiles%\Microsoft Shared\MSInfo\Server.exe
- %TEMP%\WER440c.dir00\calc.exe.hdmp
- %TEMP%\WERaaef.dir00\calc.exe.mdmp
- %TEMP%\WERaaef.dir00\calc.exe.hdmp
- %TEMP%\WER440c.dir00\appcompat.txt
- %TEMP%\WER440c.dir00\manifest.txt
- %TEMP%\WER6460.dir00\appcompat.txt
- %TEMP%\WER6460.dir00\manifest.txt
- %TEMP%\WER5dfa.dir00\manifest.txt
- %TEMP%\WER6460.dir00\calc.exe.hdmp
- %TEMP%\WER9c75.dir00\calc.exe.mdmp
- %TEMP%\WER9c75.dir00\manifest.txt
- %TEMP%\WERced4.dir00\calc.exe.mdmp
- %TEMP%\WER9c75.dir00\calc.exe.hdmp
- %TEMP%\WER9c75.dir00\appcompat.txt
- %TEMP%\WER13c3.dir00\calc.exe.hdmp
- %TEMP%\WER13c3.dir00\appcompat.txt
- %TEMP%\WERf9c8.dir00\manifest.txt
- %TEMP%\WER13c3.dir00\calc.exe.mdmp
- %TEMP%\WER13c3.dir00\manifest.txt
- %TEMP%\WER6460.dir00\calc.exe.mdmp
- %TEMP%\WER5dfa.dir00\appcompat.txt
- %TEMP%\WER5dfa.dir00\calc.exe.mdmp
- %TEMP%\WER5dfa.dir00\calc.exe.hdmp
- <SYSTEM32>\_Server.exe
- %CommonProgramFiles%\Microsoft Shared\MSInfo\Server.exe
- %TEMP%\WER3fbe.dir00\appcompat.txt
- 'yu#####8.go1.icpcn.com':80
- yu#####8.go1.icpcn.com/ip.txt
- DNS ASK yu#####8.go1.icpcn.com
- ClassName: 'TRE20070711' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_WINHELP' WindowName: ''