Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ctfmon.exe' = '%PROGRAM_FILES%\Avira\AntiVir Desktop\svchost.exe'
- <SYSTEM32>\reg.exe ADD "HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\OpenHomePage\Command" /ve /t REG_EXPAND_SZ /d "%PROGRAM_FILES%\Internet Explorer\iexplore.exe http://www.so##u.com/index.htm?pi################################### /f
- %WINDIR%\regedit.exe /s PPS.reg
- <SYSTEM32>\ping.exe 127.0.0.1 -n 10
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\wscript.exe "%PROGRAM_FILES%\Avira\AntiVir Desktop\1.vbs"
- <SYSTEM32>\cmd.exe /c ""%PROGRAM_FILES%\Avira\AntiVir Desktop\2.bat" "
- <SYSTEM32>\attrib.exe +H "%PROGRAM_FILES%\Avira"
- %PROGRAM_FILES%\Avira\AntiVir Desktop\Internet Explorer.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.lnk
- %PROGRAM_FILES%\Avira\AntiVir Desktop\PPS.reg
- %PROGRAM_FILES%\Avira\AntiVir Desktop\1.vbs
- %PROGRAM_FILES%\Avira\AntiVir Desktop\2.bat
- %PROGRAM_FILES%\Avira\AntiVir Desktop\Config.ini
- %PROGRAM_FILES%\Avira\AntiVir Desktop\Internet Explorer.lnk
- %PROGRAM_FILES%\Avira\AntiVir Desktop\1.vbs
- %PROGRAM_FILES%\Avira\AntiVir Desktop\PPS.reg
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''