Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'antivirus' = '<SYSTEM32>\wscript.exe %APPDATA%\Suns.wsf'
- %HOMEPATH%\Start Menu\Programs\Startup\windowsupdate.Lnk
- %APPDATA%\Suns.wsf
- %APPDATA%\azzam.doc
- %APPDATA%\Suns.wsf
- %APPDATA%\azzam.doc
- ClassName: 'WordPadClass' WindowName: ''
- '<SYSTEM32>\cscript.exe' %APPDATA%\Suns.wsf
- '%ProgramFiles%\Windows NT\Accessories\wordpad.exe' "%APPDATA%\azzam.doc"