Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] '!CleanupNetMeetingDispDriver' = '"<SYSTEM32>\rundll32.exe" msconf.dll,CleanupNetMeetingDispDriver 0'
- %WINDIR%\ime\scot.exe <Полный путь к вирусу>
- <SYSTEM32>\rundll32.exe msconf.dll,CleanupNetMeetingDispDriver 128
- <SYSTEM32>\wscript.exe %WINDIR%\Provisioning\Schemas\wshellgg.vbs
- %WINDIR%\Help\config.inf
- %WINDIR%\Config\ces.bat
- %APPDATA%\Microsoft\Address Book\%USERNAME%.wab
- %WINDIR%\Help\htc.bat
- %WINDIR%\ime\scot.exe
- %WINDIR%\Provisioning\Schemas\wshell.vbs
- %WINDIR%\Provisioning\Schemas\wshellgg.vbs
- 'localhost':1037
- ClassName: 'Shell_TrayWnd' WindowName: ''