Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\Sound Max For Windows] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Sound Max For Windows] 'ImagePath' = '%WINDIR%\BEAR.EXE'
- 'Sound Max For Windows' %WINDIR%\BEAR.EXE
- %WINDIR%\syswow64\calc.exe
- iexplore.exe
- %WINDIR%\bear.exe
- C:\autorun.inf
- C:\bear.exe
- D:\autorun.inf
- D:\bear.exe
- %WINDIR%\syswow64\_bear.exe
- %WINDIR%\delsvel.bat
- %WINDIR%\bear.exe
- C:\autorun.inf
- C:\bear.exe
- D:\autorun.inf
- D:\bear.exe
- %WINDIR%\syswow64\_bear.exe
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- ClassName: 'Static' WindowName: ''
- '%WINDIR%\bear.exe'
- '%WINDIR%\syswow64\cmd.exe' /c %WINDIR%\DelSvel.bat' (со скрытым окном)
- '%WINDIR%\syswow64\calc.exe'
- '%ProgramFiles%\internet explorer\iexplore.exe'
- '%WINDIR%\syswow64\cmd.exe' /c %WINDIR%\DelSvel.bat