Техническая информация
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'Setup2233' = '%WINDIR%\START MENU\PROGRAMS\STARTUP\MySetup.exe'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'Setup3322' = '%WINDIR%\WinUpgrader88.EXE'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'AOL4290' = 'C:\COMMAND.EXE'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'PC4FREE' = '<SYSTEM32>\AOLsys.doc.EXE'
- [<HKLM>\Software\Wow6432Node\Microsoft\Internet Explorer\Main] 'Window Title' = 'Broken'
- %WINDIR%\winupgrader88.exe
- <SYSTEM32>aolsys.doc.exe
- C:\command.exe
- C:\null.exe
- C:\aol.ini
- %WINDIR%\winupgrader88.exe
- C:\command.exe
- ClassName: 'Shell_traywnd' WindowName: ''
- ClassName: 'Progman' WindowName: ''
- '%WINDIR%\syswow64\rundll32.exe' mouse,disable' (со скрытым окном)
- '%WINDIR%\syswow64\rundll32.exe' keyboard,disable' (со скрытым окном)
- '%WINDIR%\syswow64\rundll32.exe' mouse,disable
- '%WINDIR%\syswow64\rundll32.exe' keyboard,disable