Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'KSafeTray' = '"%PROGRAM_FILES%\KSafe\KSafeTray.exe" -autorun'
- '%TEMP%\reboot.exe'
- '<SYSTEM32>\rundll32.exe' USER32.DLL,UpdatePerUserSystemParameters
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 3
- '%WINDIR%\regedit.exe' /s "%TEMP%\jinshan.reg"
- '<SYSTEM32>\attrib.exe' +s +r %WINDIR%\fonts
- %TEMP%\aut2.tmp
- %TEMP%\reboot.exe
- %TEMP%\aut3.tmp
- %TEMP%\aut1.tmp
- %TEMP%\jinshan.reg
- %HOMEPATH%\Favorites\金山导航.url
- %TEMP%\aut2.tmp
- %TEMP%\aut3.tmp
- %TEMP%\aut1.tmp
- %TEMP%\jinshan.reg
- ClassName: 'CicLoaderWndClass' WindowName: '(null)'
- ClassName: 'OleMainThreadWndClass' WindowName: '(null)'
- ClassName: 'BUTTON' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'RegEdit_RegEdit' WindowName: '(null)'