Техническая информация
- [<HKLM>\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\Open\command] '' = '"%ProgramFiles%\Internet Explorer\iexplore.exe" http://www.haha1234.com/1.htm?gg'
- %WINDIR%\explorer.exe
- %HOMEPATH%\desktop\browse.htm
- %HOMEPATH%\desktop\browse.html
- %HOMEPATH%\desktop\tree_view.htm
- %TEMP%\yyyy.bat
- %TEMP%\yyyy
- %TEMP%\yyyy
- <DRIVERS>\etc\hosts в %TEMP%\hosts
- <Полный путь к файлу>
- ClassName: 'Proxy Desktop' WindowName: ''
- ClassName: 'BaseBar' WindowName: 'ChanApp'
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- ClassName: 'SystemTray_Main' WindowName: ''
- ClassName: 'CSCHiddenWindow' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c %TEMP%\yyyy.bat' (со скрытым окном)
- '%WINDIR%\explorer.exe'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\yyyy.bat
- '<SYSTEM32>\rundll32.exe' fldrclnr.dll,Wizard_RunDLL