Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = '<Полный путь к вирусу>'
- C:\ProgramData\Microsoft\RAC\Temp\sqlDF66.tmp
- C:\ProgramData\Microsoft\RAC\Temp\sqlDF76.tmp
- <SYSTEM32>\PerfStringBackup.TMP
- %WINDIR%\inf\WmiApRpl\WmiApRpl.h
- C:\ProgramData\Microsoft\RAC\Temp\sqlDF66.tmp
- C:\ProgramData\Microsoft\RAC\Temp\sqlDF76.tmp
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- %TEMP%\~DF633F35BFBECF8CC9.TMP
- %WINDIR%\inf\WmiApRpl\0019\WmiApRpl.ini
- %WINDIR%\inf\WmiApRpl\0009\WmiApRpl.ini
- ClassName: '(null)' WindowName: '???????? ???????'
- ClassName: '(null)' WindowName: '????????? ???????'
- ClassName: '(null)' WindowName: '????????? ????? Windows'
- ClassName: '(null)' WindowName: 'Windows Task Manager'