Техническая информация
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'Ìì¸çËø' = '<Полный путь к файлу>'
- %APPDATA%\microsoft\windows\start menu\programs\startup\ìì¸çëø.lnk
- ClassName: 'Progman' WindowName: ''
- ClassName: '' WindowName: 'taskmgr.exe'
- ClassName: '' WindowName: 'sethc.exe'
- '%WINDIR%\syswow64\net.exe' user user /fullname:ÒªÃÜÂë¼ÓQQ:00000000000000000000' (со скрытым окном)
- '%WINDIR%\syswow64\net.exe' user user 11111111111111111111' (со скрытым окном)
- '%WINDIR%\syswow64\net.exe' user user /fullname:ÒªÃÜÂë¼ÓQQ:00000000000000000000
- '%WINDIR%\syswow64\net.exe' user user 11111111111111111111
- '%WINDIR%\syswow64\net1.exe' user user 11111111111111111111
- '%WINDIR%\syswow64\net1.exe' user user /fullname:ÒªÃÜÂë¼ÓQQ:00000000000000000000