Техническая информация
- %WINDIR%\Temp\ty.exe
- %WINDIR%\Temp\set.exe
- <SYSTEM32>\reg.exe add "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Start Page" /t reg_sz /d http://www.05##86.com/?zg## /f
- <SYSTEM32>\reg.exe add "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Default_Page_URL" /t reg_sz /d http://www.05##86.com/?zg## /f
- <SYSTEM32>\reg.exe add "HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\OpenHomePage\Command" /v "" /d "%PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://www.05##86.com/?zg### /f
- <SYSTEM32>\cmd.exe /c ""%TEMP%\2.tmp\ty.bat" "
- <SYSTEM32>\reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\OpenHomePage\Command" /v "" /d "%PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://www.05##86.com/?zg### /f
- %TEMP%\SkinCrafterDll.dll
- %TEMP%\aut3.tmp
- %TEMP%\vista.skf
- %TEMP%\2.tmp\ty.bat
- %WINDIR%\Temp\set.exe
- %WINDIR%\Temp\ty.exe
- %TEMP%\aut1.tmp
- %TEMP%\aut3.tmp
- %TEMP%\aut1.tmp
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''