Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Welcome' = '%WINDIR%\explorer_.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'Config' = '%WINDIR%\explorer_.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServices] 'Sevice' = '%WINDIR%\explorer_.exe'
- %WINDIR%\explorer_.exe
- %WINDIR%\temp\icq deflooder v1.0.exe
- ClassName: 'Frame' WindowName: 'GIP ver: 4230536'
- '%WINDIR%\temp\icq deflooder v1.0.exe'
- '%WINDIR%\explorer_.exe' remove
- '%WINDIR%\explorer_.exe' remove' (со скрытым окном)