Техническая информация
- [<HKLM>\Software\Classes\IE\shell\open\command] '' = '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE $'
- [<HKLM>\Software\Classes\saf\shell\open\command] '' = '%ProgramFiles%\Safari\Safari.exe $'
- расширений файлов
- '%WINDIR%\syswow64\taskkill.exe' /f /im ZhuDongFangyu.exe
- <Текущая директория>\tem9b5.tmp
- %WINDIR%\syswow64\drivers\eta\hosts
- %APPDATA%\microsoft\internet explorer\quick launch\internet explorer.ie
- %APPDATA%\microsoft\windows\start menu\internet explorer.ie
- %HOMEPATH%\desktop\internet explorer.ie
- %APPDATA%\microsoft\windows\start menu\programs\internet explorer.ie
- %APPDATA%\microsoft\internet explorer\quick launch\safari.saf
- %APPDATA%\microsoft\windows\start menu\safari.saf
- %HOMEPATH%\desktop\safari.saf
- %APPDATA%\microsoft\windows\start menu\programs\safari.saf
- ClassName: '' WindowName: ''
- ClassName: 'Progman' WindowName: ''
- ClassName: 'SHELLDLL_DefView' WindowName: ''
- '%WINDIR%\syswow64\taskkill.exe' /f /im ZhuDongFangyu.exe' (со скрытым окном)