Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ctfmon.exe' = '<SYSTEM32>\ctfmon.exe'
- <SYSTEM32>\reg.exe delete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v HotKeysCmds /f
- <SYSTEM32>\regsvr32.exe /u /s igfxpph.dll
- <SYSTEM32>\reg.exe delete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v IgfxTray /f
- <SYSTEM32>\reg.exe add HKEY_CLASSES_ROOT\Directory\Background\shellex\ContextMenuHandlers\new /ve /d {D969A300-E7FF-11d0-A93B-00A0C90F2719}
- <SYSTEM32>\reg.exe delete HKEY_CLASSES_ROOT\Directory\Background\shellex\ContextMenuHandlers /f
- <SYSTEM32>\reg.exe delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /f
- %WINDIR%\regedit.exe /s <SYSTEM32>\ime.reg
- <SYSTEM32>\cmd.exe /c ""%TEMP%\9B7F.CMD""
- <SYSTEM32>\reg.exe delete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /va /f
- <SYSTEM32>\reg.exe add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /v ctfmon.exe /d <SYSTEM32>\ctfmon.exe
- <SYSTEM32>\reg.exe delete HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /va /f
- %TEMP%\9B7F.CMD
- %TEMP%\9B7F.CMD
- %WINDIR%\Temp\Perflib_Perfdata_7e8.dat
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''