Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'mydoc' = '"%PROGRAM_FILES%\messenger\messces.exe" -d "%PROGRAM_FILES%\messenger\cishelp.dll"'
- '%PROGRAM_FILES%\Messenger\messces.exe' -d "%PROGRAM_FILES%\messenger\cishelp.dll" explorer.exe
- %WINDIR%\Explorer.EXE
- %TEMP%\08.exe
- %TEMP%\nsk3.tmp\System.dll
- %TEMP%\nsa2.tmp
- %TEMP%\nsk3.tmp\System.dll
- %TEMP%\08.exe в %PROGRAM_FILES%\Messenger\messces.exe