Техническая информация
- %TEMP%\RarSFX0\go.exe
- <SYSTEM32>\wscript.exe "%TEMP%\RarSFX0\go2.vbs"
- <SYSTEM32>\taskkill.exe /f /im ATI6.exe
- <SYSTEM32>\wscript.exe "%TEMP%\RarSFX0\go.vbs"
- %WINDIR%\regedit.exe /s "%TEMP%\HZ$D.110.2610\sfx.reg"
- %TEMP%\RarSFX0\go2.vbs
- %TEMP%\HZ$D.110.2610\sfx.reg
- %TEMP%\RarSFX0\go.vbs
- %TEMP%\RarSFX0\go.bat
- %TEMP%\RarSFX0\go.exe
- %TEMP%\RarSFX0\go.vbs
- %TEMP%\RarSFX0\go2.vbs
- %TEMP%\RarSFX0\go.bat
- %TEMP%\RarSFX0\go.exe
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''