Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'RoonPlus' = 'c:\eMvleo.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Sovgiu' = 'C:\Strokeo.exe'
- 'C:\Strokeo.exe'
- 'C:\eMvleo.exe'
- '%PROGRAM_FILES%\IEsvpor.exe'
- '<SYSTEM32>\reg.exe' ADD HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run /v Sovgiu /t REG_SZ /d C:\Strokeo.exe /f
- '<SYSTEM32>\attrib.exe' +r +s +h C:\Strokeo.exe
- '<SYSTEM32>\cmd.exe' /c "%PROGRAM_FILES%\Boot.bat"
- 360tray.exe
- %HOMEPATH%\Desktop\Internet Explorer.lnk
- C:\text.txt
- C:\Strokeo.exe
- %PROGRAM_FILES%\Boot.bat
- %PROGRAM_FILES%\IEsvpor.exe
- %TEMP%\FP1.tmp
- C:\eMvleo.exe
- C:\Strokeo.exe
- C:\eMvleo.exe
- %TEMP%\FP1.tmp
- ClassName: 'SysListView32' WindowName: '(null)'
- ClassName: 'SHELLDLL_DefView' WindowName: '(null)'
- ClassName: 'Progman' WindowName: '(null)'