Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'AdobeARMS' = '%CommonProgramFiles%\AdobeARMS.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'patches' = '1'
- <DRIVERS>\tcpip.sys
- <DRIVERS>\tcpip.sys
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%CommonProgramFiles%\AdobeARMS.exe' = '%CommonProgramFiles%\AdobeARMS....
- '%CommonProgramFiles%\AdobeARMS.exe' 308 "<Полный путь к вирусу>"
- '%CommonProgramFiles%\AdobeARMS.exe'
- %CommonProgramFiles%\AdobeARMS.exe
- %CommonProgramFiles%\AdobeARMS.exe