Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Lord' = '%WINDIR%\43\banana.bat'
- '<SYSTEM32>\attrib.exe' +r +s +h %WINDIR%\43\*.*
- '<SYSTEM32>\wscript.exe' "%WINDIR%\43\vf.vbs"
- '<SYSTEM32>\attrib.exe' +r +s +h %WINDIR%\43
- '<SYSTEM32>\attrib.exe' +h %TEMP%\ztmp
- '<SYSTEM32>\wscript.exe' "%WINDIR%\43\df.vbs"
- %WINDIR%\43\vf.vbs
- %WINDIR%\43\df.vbs
- %WINDIR%\43\banana.bat
- %TEMP%\ztmp\tmp35881.bat
- %TEMP%\ztmp\tmp36901.exe
- %WINDIR%\43\vf.vbs
- %WINDIR%\43\df.vbs
- %WINDIR%\43\banana.bat
- %TEMP%\ztmp\tmp36901.exe
- ClassName: 'Shell_TrayWnd' WindowName: ''