Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Virus Scan' = '%ALLUSERSPROFILE%\AntivirusScan.exe'
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\AntivirusScan.lnk
- %ALLUSERSPROFILE%\AntivirusScan.exe
- <SYSTEM32>\reg.exe add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /v "Virus Scan" /t REG_SZ /d "%ALLUSERSPROFILE%\AntivirusScan.exe" /f
- <SYSTEM32>\cmd.exe /c "%ALLUSERSPROFILE%\temp.bat"
- %ALLUSERSPROFILE%\swwEA3.tmp
- %TEMP%\416782.TMP
- %TEMP%\745626.TMP
- %ALLUSERSPROFILE%\RCX1.tmp
- %ALLUSERSPROFILE%\AntivirusScan.exe
- %ALLUSERSPROFILE%\temp.bat
- %TEMP%\614472.TMP
- %TEMP%\394316.TMP
- %TEMP%\767250.TMP
- %TEMP%\124660.TMP
- %TEMP%\994504.TMP
- %TEMP%\285428.TMP
- %TEMP%\416782.TMP
- %TEMP%\745626.TMP
- %ALLUSERSPROFILE%\swwEA3.tmp
- %ALLUSERSPROFILE%\temp.bat
- %ALLUSERSPROFILE%\AntivirusScan.exe
- %TEMP%\124660.TMP
- %TEMP%\394316.TMP
- %TEMP%\767250.TMP
- %TEMP%\614472.TMP
- %TEMP%\994504.TMP
- %TEMP%\285428.TMP
- %ALLUSERSPROFILE%\RCX1.tmp в %ALLUSERSPROFILE%\AntivirusScan.exe
- 'dr##.dumb1.com':443
- DNS ASK dr##.dumb1.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''