Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = '%TEMP%\RarSFX0\God mode.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'userini' = '%TEMP%\RarSFX0\God mode.exe'
- %WINDIR%\explorer.exe
- C:\1.bat
- C:\god-mode.sfx.exe
- %TEMP%\rarsfx0\god mode.exe
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'Progman' WindowName: ''
- ClassName: 'ÏðîâîäГГЁГЄ' WindowName: ''
- ClassName: 'explorer.exe ' WindowName: ''
- ClassName: '' WindowName: 'Ðåäà êòîð ðååñòðà '
- ClassName: '' WindowName: 'Íà ñòðîéêà ñèñòåìû'
- ClassName: '' WindowName: 'Äèñïåò÷åð çà äà ÷ Windows'
- ClassName: '' WindowName: 'Ðà áî÷èé ñòîë'
- ClassName: '' WindowName: 'ГЏГіГ±ГЄ'
- ClassName: '' WindowName: 'ÂûïîëГГЁГІГј'
- 'C:\god-mode.sfx.exe' -p782837273649
- '%TEMP%\rarsfx0\god mode.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""C:\1.bat" "
- '%WINDIR%\explorer.exe'