Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'OAOUIµI?µCA?µAIA???¬E??yµoI?·?Oy??µCA?IµI???' = '%APPDATA%\svchost.exe'
- <SYSTEM32>\reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\Shell" /f
- <SYSTEM32>\regini.exe %TEMP%\778476_s.ini
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoInternetIcon' = '00000000'
- %TEMP%\778476_s.ini
- %TEMP%\778476_s.ini
- %TEMP%\778476_s.ini