Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'winlog32' = '%WINDIR%\rrr'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'delBatB' = '%WINDIR%\del_key.bat'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'winlog32' = '%WINDIR%\fogotip.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'delBatB' = '%WINDIR%\del'
- %WINDIR%\fogotip.exe
- %WINDIR%\regedit.exe -s %WINDIR%\delVreg.reg
- %WINDIR%\regedit.exe -s %WINDIR%\startVreg.reg
- %WINDIR%\fogotip.exe
- %WINDIR%\del_key.bat
- %WINDIR%\startVreg.reg
- %WINDIR%\delVreg.reg
- ClassName: 'RegEdit_RegEdit' WindowName: ''