Техническая информация
- %WINDIR%\de5148ff.reg
- %ProgramFiles%\internet explorer\acpi.vxd
- %ProgramFiles%\internet explorer\_file0000.tmp
- %WINDIR%\system\<Имя файла>.exe
- %WINDIR%\de5148ff.reg
- %ProgramFiles%\internet explorer\acpi.vxd
- %WINDIR%\de5148ff.reg
- %ProgramFiles%\internet explorer\acpi.vxd
- DNS ASK rc###rtinez.com
- DNS ASK cl######ebenelli.globat.com
- ClassName: '145432A' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- '%WINDIR%\syswow64\regedit.exe' /s %WINDIR%\DE5148FFReg' (со скрытым окном)
- '%WINDIR%\syswow64\regedit.exe' /s %WINDIR%\DE5148FFReg