Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\cftmonaa.lnk
- '%PROGRAM_FILES%\Your Product\cftmonaa.exe'
- '%TEMP%\_ir_sf7_temp_0\irsetup.exe' "__IRAFN:<Полный путь к вирусу>"
- %PROGRAM_FILES%\Your Product\msg.exe
- %PROGRAM_FILES%\Your Product\LAUNCH.EXE
- %PROGRAM_FILES%\Your Product\fucked.bmp
- %PROGRAM_FILES%\Your Product\taskkill.exe
- %PROGRAM_FILES%\Your Product\reg.exe
- %PROGRAM_FILES%\Your Product\netsh.exe
- %PROGRAM_FILES%\Your Product\bou1.bat
- %TEMP%\_ir_sf7_temp_0\irsetup.dat
- %TEMP%\_ir_sf7_temp_0\irsetup.exe
- %PROGRAM_FILES%\Your Product\format.com
- %PROGRAM_FILES%\Your Product\cftmonaa.exe
- %PROGRAM_FILES%\Your Product\cdr.exe
- %TEMP%\_ir_sf7_temp_0\irsetup.exe
- %TEMP%\_ir_sf7_temp_0\irsetup.dat
- ClassName: 'MS_WINHELP' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'