Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'slwc' = '<SYSTEM32>\slwc.exe'
- <SYSTEM32>\cacls.exe "<SYSTEM32>\charmap.exe" /E /G "%USERNAME%":F
- <SYSTEM32>\cacls.exe "<SYSTEM32>\calc.exe" /E /G "%USERNAME%":F
- <SYSTEM32>\cacls.exe "<SYSTEM32>\browseui.dll" /E /G "%USERNAME%":F
- <SYSTEM32>\cacls.exe "<SYSTEM32>\cmd.exe" /E /G "%USERNAME%":F
- <SYSTEM32>\cacls.exe "%WINDIR%\explorer.exe" /E /G "%USERNAME%":F
- <SYSTEM32>\cacls.exe "<SYSTEM32>\Defrag.exe" /E /G "%USERNAME%":F
- <SYSTEM32>\cacls.exe "<SYSTEM32>\control.exe" /E /G "%USERNAME%":F
- <SYSTEM32>\taskkill.exe /F /IM "WinList.exe"
- <SYSTEM32>\taskkill.exe /F /IM "UBERIC~1.EXE"
- <SYSTEM32>\taskkill.exe /F /IM "ROCKET~1.EXE"
- <SYSTEM32>\taskkill.exe /F /IM "VIRTUA~1.EXE"
- <SYSTEM32>\cacls.exe "<SYSTEM32>\batmeter.dll" /E /G "%USERNAME%":F
- <SYSTEM32>\taskkill.exe /F /IM "explorer.exe"
- <SYSTEM32>\taskkill.exe /F /IM "YzShadow.exe"
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\SLTrans\~GLH0000.TMP
- <SYSTEM32>\SLTrans\~GLH0001.TMP
- %TEMP%\GLC1.tmp
- %TEMP%\GLW2.tmp
- <SYSTEM32>\SLTrans\sl.sif
- %TEMP%\GLW2.tmp
- ClassName: '' WindowName: ''
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''