Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Hst' = '"%WINDIR%\Temp\hstart.exe" /noconsole /d="%WINDIR%\temp\" "%WINDIR%\temp\write.bat"'
- '%WINDIR%\Temp\svchost.exe' 1900 /quiet
- '%WINDIR%\Temp\hstart.exe' /noconsole /silent /d="%WINDIR%\temp\" "%WINDIR%\temp\main.bat"
- '%WINDIR%\regedit.exe' /s runonce.reg
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\temp\main.bat
- %WINDIR%\Temp\hstart.exe
- %WINDIR%\Temp\realdate.com
- %WINDIR%\Temp\runonce.reg
- %WINDIR%\Temp\wget.exe
- %WINDIR%\Temp\svchost.exe
- %WINDIR%\Temp\lc.exe
- %WINDIR%\Temp\run.reg
- %WINDIR%\Temp\os.bat
- %WINDIR%\Temp\main.bat
- %WINDIR%\Temp\check.bat
- %WINDIR%\Temp\write.bat
- %WINDIR%\Temp\rest.bat
- %WINDIR%\Temp\r.bat
- %WINDIR%\Temp\runonce.reg
- ClassName: 'RegEdit_RegEdit' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'