Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'GOOGLEDBL2' = '%APPDATA%\httpd.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'GOOGLEDBL1' = '%APPDATA%\httpd.exe'
- %APPDATA%\httpd.exe
- %TEMP%\Launcher.exe
- <SYSTEM32>\reg.exe ADD HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce /V GOOGLEDBL1 /D "%APPDATA%\httpd.exe" /f
- <SYSTEM32>\reg.exe ADD HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce /V GOOGLEDBL2 /D "%APPDATA%\httpd.exe" /f
- <SYSTEM32>\cmd.exe /c ""%APPDATA%\httpd.bat" "
- <SYSTEM32>\reg.exe DELETE HKCU\AppEvents\Schemes\Apps\Explorer\Navigating\.Current /V "" /f
- %APPDATA%\httpd.config
- %APPDATA%\httpd.bat
- %TEMP%\Launcher.exe
- %APPDATA%\httpd.exe
- %APPDATA%\httpd.bat
- ClassName: 'Shell_TrayWnd' WindowName: ''