Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'UUSeei' = 'c:\Kuwoi.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Bitocmet' = 'C:\KMPlayir.exe'
- 'C:\KMPlayir.exe'
- 'C:\Kuwoi.exe'
- '%PROGRAM_FILES%\CoolIE.exe'
- '<SYSTEM32>\reg.exe' ADD HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run /v Bitocmet /t REG_SZ /d C:\KMPlayir.exe /f
- '<SYSTEM32>\attrib.exe' +r +s +h C:\KMPlayir.exe
- '<SYSTEM32>\cmd.exe' /c "%PROGRAM_FILES%\Boot.bat"
- 360tray.exe
- %HOMEPATH%\Desktop\Internet Explorer.lnk
- C:\text.txt
- C:\KMPlayir.exe
- %PROGRAM_FILES%\Boot.bat
- %PROGRAM_FILES%\CoolIE.exe
- %TEMP%\FP1.tmp
- C:\Kuwoi.exe
- C:\KMPlayir.exe
- C:\Kuwoi.exe
- %TEMP%\FP1.tmp
- ClassName: 'SysListView32' WindowName: ''
- ClassName: 'SHELLDLL_DefView' WindowName: ''
- ClassName: 'Progman' WindowName: ''