Техническая информация
- [<HKLM>\SOFTWARE\Classes\Folder\shell\open\command] '' = '%SystemRoot%\Explorer.exe /e,/idlist,%I,%L'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'zzzNoAutoRun' = 'c:\Recycled\NoAutorun.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'zzzNoAutoRun' = 'c:\Recycled\NoAutorun.exe'
- <Имя диска съемного носителя>:\Recycled\NoAutorun.exe
- <Имя диска съемного носителя>:\autorun.inf
- скрытых файлов
- C:\Recycled\NoAutorun.exe
- <SYSTEM32>\reg.exe delete HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System /f /v DisableTaskMgr
- <SYSTEM32>\reg.exe delete HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System /f /v DisableTaskMgr
- <SYSTEM32>\reg.exe delete HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System /f /v DisableRegistryTools
- <SYSTEM32>\reg.exe delete HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System /f /v DisableRegistryTools
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFolderOptions' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoRun' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoStartMenuSubFolders' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] 'NoFolderOptions' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] 'NoRun' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] 'NoStartMenuSubFolders' = '00000000'
- C:\Recycled\NoAutorun.bat
- C:\autorun.info
- C:\Recycled\NoAutorun.exe
- <Имя диска съемного носителя>:\Recycled\NoAutorun.exe
- C:\Recycled\NoAutorun.bat
- <Полный путь к вирусу>
- C:\autorun.info
- C:\Recycled\NoAutorun.exe
- <Имя диска съемного носителя>:\autorun.inf
- C:\Recycled\NoAutorun.exe.0
- ClassName: 'Indicator' WindowName: ''