Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'SoundMax' = '"<SYSTEM32>\SoundMax.exe"'
- [<HKLM>\SOFTWARE\Microsoft\Internet Explorer\Extensions\{6096E38F-5AC1-4391-8EC4-75DFA92FB32F}] 'Exec' = 'http://s.fala123.cn'
- Cредство проверки системных файлов (SFC)
- <SYSTEM32>\soundmax.exe
- %WINDIR%\regedit.exe /s %WINDIR%\\system32\\soundmax.reg
- <SYSTEM32>\wscript.exe "<SYSTEM32>\soundmax.vbs"
- <SYSTEM32>\soundmax.reg
- <SYSTEM32>\soundmax.vbs
- <SYSTEM32>\soundmax.exe
- <SYSTEM32>\baidu.ico
- <SYSTEM32>\soundmax.exe
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''