Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'run' = '%WINDIR%\system1.exe'
- %WINDIR%\system1.exe
- %WINDIR%\syswow64\oobe\info\backgrounds\backgrounddefault.jpg
- C:\documents and settings\all users\application data\microsoft\user account pictures\user.bmp
- %WINDIR%\aver.ico
- %WINDIR%\system1.exe
- '%WINDIR%\syswow64\net1.exe' user "user" /FULLNAME:"ÒªÃÜÂëÁªÏµQQ1143781940"' (со скрытым окном)
- '%WINDIR%\syswow64\net1.exe' user "user" "qq.com"' (со скрытым окном)
- '%WINDIR%\syswow64\net1.exe' user "user" /FULLNAME:"ÒªÃÜÂëÁªÏµQQ1143781940"
- '%WINDIR%\syswow64\net1.exe' user "user" "qq.com"