Техническая информация
- %WINDIR%\regedit.exe /e %TEMP%\TXMP.~ "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe"
- <SYSTEM32>\cmd.exe /c %TEMP%\svohost.bat
- <SYSTEM32>\CatRoot\TMP8.tmp
- <SYSTEM32>\CatRoot\TMP7.tmp
- <SYSTEM32>\CatRoot\TMP6.tmp
- <SYSTEM32>\CatRoot\TMPB.tmp
- <SYSTEM32>\CatRoot\TMPA.tmp
- <SYSTEM32>\CatRoot\TMP9.tmp
- <SYSTEM32>\CatRoot\TMP5.tmp
- <SYSTEM32>\CatRoot\TMP1.tmp
- <SYSTEM32>\nppmgmt.dll
- %TEMP%\svohost.bat
- <SYSTEM32>\CatRoot\TMP4.tmp
- <SYSTEM32>\CatRoot\TMP3.tmp
- <SYSTEM32>\CatRoot\TMP2.tmp
- <SYSTEM32>\CatRoot\TMP7.tmp
- <SYSTEM32>\CatRoot\TMP6.tmp
- <SYSTEM32>\CatRoot\TMP5.tmp
- <SYSTEM32>\CatRoot\TMPA.tmp
- <SYSTEM32>\CatRoot\TMP9.tmp
- <SYSTEM32>\CatRoot\TMP8.tmp
- <SYSTEM32>\CatRoot\TMP4.tmp
- <SYSTEM32>\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\TimeStamp
- <SYSTEM32>\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\TimeStamp
- %TEMP%\svohost.bat
- <SYSTEM32>\CatRoot\TMP3.tmp
- <SYSTEM32>\CatRoot\TMP1.tmp
- <SYSTEM32>\CatRoot\TMP2.tmp
- <SYSTEM32>\CatRoot2\edb.log в <SYSTEM32>\CatRoot2\edb00001.log
- ClassName: 'RegEdit_RegEdit' WindowName: ''