Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '"%TEMP%\userinit.exe"'
- Редактора реестра (RegEdit)
- <SYSTEM32>\taskkill.exe /F /IM icq.exe
- <SYSTEM32>\taskkill.exe /F /IM qip.exe
- <SYSTEM32>\taskkill.exe /F /IM miranda.exe
- <SYSTEM32>\taskkill.exe /F /IM chrome.exe
- <SYSTEM32>\taskkill.exe /F /IM opera.exe
- <SYSTEM32>\taskkill.exe /F /IM explorer.exe
- <SYSTEM32>\taskkill.exe /F /IM iexplore.exe
- <SYSTEM32>\taskkill.exe /F /IM firefox.exe
- %WINDIR%\Explorer.EXE
- firefox.exe
- ICQ.exe
- opera.exe
- iexplore.exe
- chrome.exe
- qip.exe
- %TEMP%\userinit.exe
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''