Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\arswp3.exe] 'Debugger' = 'shutdown -r -t 20'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ksmgui.exe] 'Debugger' = 'shutdown -r -t 20'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360se.exe] 'Debugger' = 'shutdown -r -t 20'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '<SYSTEM32>\internst.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SuperKiller.exe] 'Debugger' = 'shutdown -r -t 20'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ArSwp.exe] 'Debugger' = 'shutdown -r -t 20'
- '%WINDIR%\Temp\123.exe' %WINDIR%\temp\123.ini
- '%WINDIR%\regedit.exe' /s %WINDIR%\fonts\internat.reg
- '<SYSTEM32>\wscript.exe' "%WINDIR%\fonts\internat.vbs"
- '%WINDIR%\regedit.exe' /s %WINDIR%\temp\ie.reg
- %WINDIR%\Fonts\tb.ico
- %WINDIR%\Fonts\internat.vbs
- %HOMEPATH%\Desktop\QQ°®±нЗй°ь.lnk
- <SYSTEM32>\internst.exe
- %WINDIR%\Fonts\internat.reg
- %WINDIR%\Temp\123.exe
- %WINDIR%\Temp\ie.reg
- %WINDIR%\Temp\123.ini
- 'to###.0557vip.cn':8001
- 'localhost':1036
- DNS ASK to###.0557vip.cn
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''