Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Ask Toolbar Chrome' = '%ProgramFiles(x86)%\Google\Chrome\Application\Ask Toolbar Chrome.lnk'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Ask Toolbar Firefox' = '%ProgramFiles(x86)%\Mozilla Firefox\Ask Toolbar Firefox.lnk'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'svchost' = '%APPDATA%\svchost\svchost.exe'
- %TEMP%\sqli dumper v.8.0.exe
- %ProgramFiles(x86)%\google\chrome\application\ask toolbar chrome.exe
- %ProgramFiles(x86)%\google\chrome\application\ask toolbar chrome.lnk
- %ProgramFiles(x86)%\mozilla firefox\ask toolbar firefox.exe
- %ProgramFiles(x86)%\mozilla firefox\ask toolbar firefox.lnk
- %APPDATA%\svchost\svchost.exe
- %ProgramFiles(x86)%\google\chrome\application\ask toolbar chrome.lnk
- %ProgramFiles(x86)%\mozilla firefox\ask toolbar firefox.lnk
- '%TEMP%\sqli dumper v.8.0.exe'
- '%WINDIR%\syswow64\reg.exe' ADD "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "svchost" /t REG_SZ /F /D "%APPDATA%\svchost\svchost.exe' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "svchost" /t REG_SZ /F /D "%APPDATA%\svchost\svchost.exe