Техническая информация
- [<HKCU>\Control Panel\Desktop] 'SCRNSAVE.EXE' = '%APPDATA%\Microsoft\Windows\dashrain.scr'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '<Имя вируса>' = '<Полный путь к вирусу>'
- <SYSTEM32>\attrib.exe -R -H -S "<SYSTEM32>\wifihi.exe"
- <SYSTEM32>\reg.exe ADD "HKCU\Control Panel\Desktop" /v ScreenSaveTimeOut /t REG_SZ /d "60" /f
- <SYSTEM32>\attrib.exe -R -H -S "%APPDATA%\disksecure"
- <SYSTEM32>\attrib.exe +R +H +S "<SYSTEM32>\wifihi.exe"
- <SYSTEM32>\reg.exe ADD "HKCU\Control Panel\Desktop" /v ScreenSaveActive /t REG_SZ /d "1" /f
- <SYSTEM32>\attrib.exe -R -H -S "%APPDATA%\Microsoft\Windows\dashrain.scr"
- <SYSTEM32>\attrib.exe -R -H -S "%APPDATA%\disksecure\disksecure.exe"
- <SYSTEM32>\reg.exe ADD "HKCU\Control Panel\Desktop" /v "SCRNSAVE.EXE" /t REG_SZ /d "%APPDATA%\Microsoft\Windows\dashrain.scr" /f
- <SYSTEM32>\attrib.exe +R +H +S "%APPDATA%\Microsoft\Windows\dashrain.scr"
- <SYSTEM32>\wifihi.exe
- %APPDATA%\Microsoft\Windows\dashrain.scr
- %APPDATA%\disksecure\disksecure.exe
- <SYSTEM32>\wifihi.exe
- %APPDATA%\Microsoft\Windows\dashrain.scr
- ClassName: 'Indicator' WindowName: ''