Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'lsass.exe' = '%WINDIR%\lsass.exe'
- %TEMP%\zelix.scr /S
- <SYSTEM32>\rundll32.exe <SYSTEM32>\shell32.dll,OpenAs_RunDLL %TEMP%\behoproexp.cam
- ClassName: 'TibiaClient' WindowName: ''
- %WINDIR%\lsass.exe
- %TEMP%\behoproexp.cam
- %TEMP%\zelix.scr
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''