Техническая информация
- <SYSTEM32>\wscript.exe "%TEMP%\1.tmp\mbox.vbs" - kapatmal¤.vbs
- %WINDIR%\regedit.exe /S "%HOMEPATH%\Local Settings\Temp.\DefOpen.reg"
- <SYSTEM32>\cmd.exe /c ""%TEMP%\1.tmp\ie-hэz-paket.bat" "
- [<HKCU>\Software\Microsoft\Internet Explorer\Main] 'Window Title' = 'www.sordum.com'
- %TEMP%\DefOpen.reg
- %TEMP%\1.tmp\mbox.vbs
- %TEMP%\1.tmp\ie-hэz-paket.bat
- %TEMP%\DefOpen.reg
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''