Техническая информация
- [<HKLM>\SOFTWARE\Classes\HTTP\shell\open\command] '' = '%PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE www.babaw.com'
- '%WINDIR%\regedit.exe' /s games.reg
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\RarSFX0\games.bat" "
- %TEMP%\RarSFX0\games.reg
- %TEMP%\RarSFX0\games.bat
- %TEMP%\RarSFX0\games.reg
- %TEMP%\RarSFX0\games.bat
- %TEMP%\RarSFX0\games.reg
- %TEMP%\RarSFX0\games.bat
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''