Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'wextract_cleanup0' = 'rundll32.exe <SYSTEM32>\advpack.dll,DelNodeRunDLL32 "%TEMP%\IXP000.TMP\"'
- '%TEMP%\7zS1.tmp\MSIStart.exe' AdwareBot
- '%TEMP%\IXP000.TMP\ADWARE~1.EXE'
- '<SYSTEM32>\msiexec.exe' /V
- '<SYSTEM32>\msiexec.exe' /i AdwareBot.msi
- %TEMP%\7zS1.tmp\AdwareBot\SpyCleaner.dll
- %TEMP%\7zS1.tmp\MSIStart.exe
- %TEMP%\7zS1.tmp\AdwareBot\AdwareBot.srv.exe
- %TEMP%\284e5.msi
- %TEMP%\7zS1.tmp\AdwareBot\zlib.dll
- %TEMP%\7zS1.tmp\AdwareBot\TCL.dll
- %TEMP%\7zS1.tmp\AdwareBot\vistaCPtasks.xml
- %TEMP%\7zS1.tmp\AdwareBot64.msi
- %TEMP%\7zS1.tmp\AdwareBot.msi
- %TEMP%\7zS1.tmp\AdwareBot\AdwareBot.exe
- %TEMP%\7zS1.tmp\AdwareBot\AdwareBot.url
- %TEMP%\7zS1.tmp\AdwareBot\DataBase.ref
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'